{"id":"CVE-2026-54768","title":"WPGraphQL provides a GraphQL API for WordPress sites","summary":"WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordR…","severity":"medium","cwe":["CWE-204"],"vendor":"wp-graphql","product":"wp-graphql/wp-graphql","affected":["wp-graphql/wp-graphql <= 2.6.0"],"published":"2026-07-31","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:30:11.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54768","references":[{"url":"https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql/v2.15.1","label":"security-advisories@github.com"},{"url":"https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv","label":"security-advisories@github.com"},{"url":"https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-jhh7-832h-f8hv"}],"tags":["nvd","ghsa","composer"],"epss":0.00344,"epssPercentile":0.27895,"aliases":["GHSA-jhh7-832h-f8hv"],"ecosystem":"composer","ingestedAt":"2026-07-31T23:04:59.912Z","slug":"CVE-2026-54768","body":"## Overview\n\nWPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-54768)\n\nAffected packages:\n\n- `wp-graphql/wp-graphql <= 2.6.0`\n\nSource: https://github.com/advisories/GHSA-jhh7-832h-f8hv","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}