What is CVE-2026-54768?
CVE-2026-54768 is a vulnerability in the WPGraphQL plugin where the deprecated 'user' field in SendPasswordResetEmailPayload allows unauthenticated callers to identify existing author-class accounts and retrieve public profile fields via the sendPasswordResetEmail mutation. Versions from 2.0.0 to 2.15.1 are affected, immediate update is recommended.
Azərbaycanca: CVE-2026-54768 WPGraphQL plaginində köhnəlmiş 'user' sahəsi vasitəsilə autentifikasiya olunmamış şəxsə 'sendPasswordResetEmail' mutasiyası ilə müəllif sinifli hesabların mövcudluğunu müəyyən etməyə və açıq profil məlumatlarını əldə etməyə imkan verən zəiflikdir. 2.0.0-dan 2.15.1-ə qədər versiyalar təsirlənir, dərhal yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ1
What operation does CVE-2026-54768 allow an unauthenticated user to perform via the WPGraphQL plugin?
An unauthenticated caller can identify existing author-class accounts and retrieve public profile fields using the deprecated 'user' field in the sendPasswordResetEmail mutation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.