WordPress plugin WPGraphQL access control error vulnerability

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a set of blogging platforms developed using the PHP language. WordPress plugin is an application plugin. WordPress plugin WPGraphQL versions prior to 0.3.5 are vulnerable to an access control error that results from a failure to properly restrict user access to information about other user roles. A remote attacker could forge GraphQL queries to retrieve the account roles of each user on the site.Read More

