Impact
WPGraphQL Smart Cache for WordPress lacks an authorization check and does not validate caller‑supplied query identifiers before storing persisted queries, allowing an unauthenticated user to register any GraphQL query document and claim arbitrary aliases. Based on the description, it is inferred that an attacker can inject malicious queries that the site’s frontend may execute later, potentially revealing sensitive data or altering application behavior. The flaw permits the creation of persisted queries that can be used repeatedly, giving the attacker extended influence over the site’s data retrieval logic.
Affected Systems
Any WordPress site running WPGraphQL Smart Cache with a version lower than 2.3.2 is affected. The plugin vendor’s advisory indicates that upgrading to 2.3.2 or later is required; sites using 2.3.1 or earlier lack the necessary authorization check, implying they remain vulnerable.
Risk and Exploitability
The vulnerability does not require prior authentication, so an attacker only needs network access to the site’s GraphQL endpoint. The CVSS score of 6.5 reflects a medium severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. Based on the description, it is inferred that the attack path relies on sending a POST request containing a crafted query identifier, enabling the attacker to register persisted queries without being authenticated. Although not listed in the CISA KEV catalog, the lack of authorization presents a significant inherent risk that could be exploited if an attacker succeeds in publishing malicious queries.
OpenCVE Enrichment