Impact
The WPGraphQL Smart Cache plugin for WordPress allows unauthenticated users to store a persisted GraphQL query and assign a query alias without any authorization check. Because no caller‑supplied query identifier is validated, an attacker can publish arbitrary query documents and claim aliases that the site’s own frontend may later use. This capability could potentially allow an attacker to influence the site’s data retrieval logic (inference).
Affected Systems
The vulnerability affects the WPGraphQL Smart Cache plugin version 2.3.1 and earlier. All WordPress sites that have this plugin installed and have not upgraded to 2.3.2 or later are susceptible.
Risk and Exploitability
The flaw does not require any authentication, so a remote attacker can exploit it from any network that can reach the site. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. However, the absence of an authentication check increases the inherent risk, and the potential impact includes the ability to register arbitrary persisted queries on the target site. The exact exploitation probability remains unknown.
OpenCVE Enrichment