<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:08:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-374217</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-374217</link>
      <description>EUVD-2026-374217</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-374217</guid>
    </item>
    <item>
      <title>fkie_cve-2026-88974</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88974</link>
      <description>&lt;p&gt;WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor&amp;#39;s own draft without editorial approval or modify the Contributor&amp;#39;s previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor&amp;#39;s own draft without editorial approval or modify the Contributor&amp;#39;s previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-88974</guid>
    </item>
    <item>
      <title>GHSA-5mmc-8pc9-wggg — WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5mmc-8pc9-wggg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wp-graphql/wp-graphql&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;WPGraphQL 2.19.0 contains an authorization bypass in the `updatePost` mutation. An authenticated WordPress Contributor can change one of their own draft posts to `PUBLISH` despite lacking the `publish_posts` capability. The same mutation also permits the Contributor to modify their own previously published posts despite lacking `edit_published_posts` and failing WordPress&amp;#39;s object-level `edit_post` capability check.&lt;/p&gt;
&lt;p&gt;This bypasses the standard WordPress editorial workflow. The WordPress REST API correctly rejects the equivalent operations for the same user.&lt;/p&gt;
&lt;p&gt;## Affected software&lt;/p&gt;
&lt;p&gt;- Plugin: WPGraphQL
- Plugin slug: `wp-graphql`
- Confirmed affected version: `2.19.0`
- Plugin URL: https://wordpress.org/plugins/wp-graphql/
- Repository: https://github.com/wp-graphql/wp-graphql
- WordPress version used for testing: `7.0.2`
- WPGraphQL configuration: default settings&lt;/p&gt;
&lt;p&gt;Only version 2.19.0 is claimed as confirmed because that is the version tested. The same authorization pattern appears in earlier source history, but those releases were not independently tested.&lt;/p&gt;
&lt;p&gt;## Vulnerability type&lt;/p&gt;
&lt;p&gt;- Broken access control / authorization bypass
- CWE-863: Incorrect Authorization
- OWASP 2021: A01 – Broken Access Control
- Minimum required role: Contributor&lt;/p&gt;
&lt;p&gt;## Technical cause&lt;/p&gt;
&lt;p&gt;`src/Mutation/PostObjectUpdate.php` checks only the post type&amp;#39;s collection-level `edit_posts` capability:&lt;/p&gt;
&lt;p&gt;```php
if ( ! isset( $post_type_object-&amp;gt;cap-&amp;gt;edit_posts ) || ! current_user_can( $post_type_object-&amp;gt;ca…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: wp-graphql/wp-graphql&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;WPGraphQL 2.19.0 contains an authorization bypass in the `updatePost` mutation. An authenticated WordPress Contributor can change one of their own draft posts to `PUBLISH` despite lacking the `publish_posts` capability. The same mutation also permits the Contributor to modify their own previously published posts despite lacking `edit_published_posts` and failing WordPress&amp;#39;s object-level `edit_post` capability check.&lt;/p&gt;
&lt;p&gt;This bypasses the standard WordPress editorial workflow. The WordPress REST API correctly rejects the equivalent operations for the same user.&lt;/p&gt;
&lt;p&gt;## Affected software&lt;/p&gt;
&lt;p&gt;- Plugin: WPGraphQL
- Plugin slug: `wp-graphql`
- Confirmed affected version: `2.19.0`
- Plugin URL: https://wordpress.org/plugins/wp-graphql/
- Repository: https://github.com/wp-graphql/wp-graphql
- WordPress version used for testing: `7.0.2`
- WPGraphQL configuration: default settings&lt;/p&gt;
&lt;p&gt;Only version 2.19.0 is claimed as confirmed because that is the version tested. The same authorization pattern appears in earlier source history, but those releases were not independently tested.&lt;/p&gt;
&lt;p&gt;## Vulnerability type&lt;/p&gt;
&lt;p&gt;- Broken access control / authorization bypass
- CWE-863: Incorrect Authorization
- OWASP 2021: A01 – Broken Access Control
- Minimum required role: Contributor&lt;/p&gt;
&lt;p&gt;## Technical cause&lt;/p&gt;
&lt;p&gt;`src/Mutation/PostObjectUpdate.php` checks only the post type&amp;#39;s collection-level `edit_posts` capability:&lt;/p&gt;
&lt;p&gt;```php
if ( ! isset( $post_type_object-&amp;gt;cap-&amp;gt;edit_posts ) || ! current_user_can( $post_type_object-&amp;gt;ca…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5mmc-8pc9-wggg</guid>
    </item>
  </channel>
</rss>
