CVE-2021-47959

WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads to trigger server out-of-memory conditions and MySQL connection errors.
Configurations

No configuration.

History

15 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 19:16

Updated : 2026-05-18 17:05


NVD link : CVE-2021-47959

Mitre link : CVE-2021-47959

CVE.ORG link : CVE-2021-47959


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling