Vulnerability Description
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.
Related Weaknesses (CWE)
References
- https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql/v2.15.1
- https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv
- https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv
FAQ
What is CVE-2026-54768?
CVE-2026-54768 is a documented vulnerability. WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-cla...
How severe is CVE-2026-54768?
CVSS scoring is not yet available for CVE-2026-54768. Check NVD for updates.
Is there a patch for CVE-2026-54768?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.