{"id":"CVE-2026-88974","published":"2026-09-23T15:17:23.893","lastModified":"2026-09-23T18:12:04.247","description":"WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the object-level edit_post capability or require publish_posts for public status transitions. An authenticated Contributor can therefore publish the Contributor's own draft without editorial approval or modify the Contributor's previously published post despite lacking edit_published_posts, while posts owned by other authors remain protected. This issue is fixed in version 2.22.2.","cvssScore":5.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","cwes":["CWE-863"],"vendors":[],"products":[],"references":[{"url":"https://github.com/wp-graphql/wp-graphql/commit/55441663eaa33c3f2e05de038c8286c845916461","tags":[]},{"url":"https://github.com/wp-graphql/wp-graphql/pull/4270","tags":[]},{"url":"https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql%2Fv2.22.2","tags":[]},{"url":"https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg","tags":[]},{"url":"https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg","tags":[]}],"exploitRefs":[{"url":"https://github.com/wp-graphql/wp-graphql/commit/55441663eaa33c3f2e05de038c8286c845916461","tags":[]},{"url":"https://github.com/wp-graphql/wp-graphql/pull/4270","tags":[]},{"url":"https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql%2Fv2.22.2","tags":[]},{"url":"https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg","tags":[]},{"url":"https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-5mmc-8pc9-wggg","tags":[]}],"hasPoc":true,"ai":null}