Impact
Press use the Gato GraphQL plugin to increase their privileges beyond what their role normally permits. The flaw stems from insufficient authorization checks, allowing the attacker to perform potentially gain full control of the site.
Affected Systems
The affected component is the Gato GraphQL WordPress plugin, vendor Gato GraphQL 19.2.3. Sites that have not applied the latest release are susceptible.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. The EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the website; the attacker must possess a subscriber account or the site must be misconfigured to allow anonymous GraphQL queries. Successful exploitation would enable the attacker to gain elevated capabilities, compromising confidentiality, integrity, and availability of the WordPress installation.
OpenCVE Enrichment