CVE-2026-54768

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Aug 2026, 21:16

Type Values Removed Values Added
References () https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv - () https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv -

31 Jul 2026, 23:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-31 23:17

Updated : 2026-08-03 21:16


NVD link : CVE-2026-54768

Mitre link : CVE-2026-54768

CVE.ORG link : CVE-2026-54768


JSON object : View

Products Affected

No product.

CWE
CWE-204

Observable Response Discrepancy