Learn about CVE-2019-9879 affecting WPGraphQL 0.2.3 plugin for WordPress. Discover the impact, technical details, and mitigation steps for this vulnerability.
WordPress plugin WPGraphQL 0.2.3 allows remote attackers to create new user accounts with admin privileges.
Understanding CVE-2019-9879
When the new user registration feature is activated in the WPGraphQL 0.2.3 plugin for WordPress, a vulnerability enables attackers to create a new user account with administrative privileges.
What is CVE-2019-9879?
The vulnerability in WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges when new user registrations are allowed. This issue is specifically related to the registerUser mutation.
The Impact of CVE-2019-9879
Technical Details of CVE-2019-9879
The technical details of the CVE-2019-9879 vulnerability are as follows:
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protect your system from CVE-2019-9879 with the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates