---
id: CVE-2026-62102
title: WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability
summary: Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-266
vendor: Gato GraphQL
product: Gato GraphQL
affected:
  - gato_graphql >= n/a <= 19.2.3
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T18:46:23.375967Z'
published: '2026-09-11'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T20:29:14.133Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-62102'
references:
  - url: >-
      https://patchstack.com/database/wordpress/plugin/gatographql/vulnerability/wordpress-gato-graphql-plugin-19-2-3-privilege-escalation-vulnerability?_s_id=cve
tags:
  - cve.org
epss: 0.00417
epssPercentile: 0.33277
ingestedAt: '2026-09-14T11:11:19.882Z'
---

## Overview

Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.

## Affected

- `gato_graphql >= n/a <= 19.2.3`

## Remediation

Update the WordPress Gato GraphQL plugin to the latest available version (at least 19.2.4).
