VYPR
High severity7.5NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026

CVE-2026-40762

CVE-2026-40762

Description

Unauthenticated SQL injection in WPGraphQL plugin for WordPress versions before 2.11.1 allows remote attackers to interact with the database.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated SQL injection in WPGraphQL plugin for WordPress versions before 2.11.1 allows remote attackers to interact with the database.

Vulnerability

The WPGraphQL plugin for WordPress versions prior to 2.11.1 contains an unauthenticated SQL injection vulnerability [1]. The flaw exists in the GraphQL endpoint, allowing an attacker to inject arbitrary SQL queries without requiring authentication. Affected versions are all releases before 2.11.1.

Exploitation

An attacker can exploit this vulnerability by sending crafted GraphQL requests to the vulnerable endpoint [1]. No authentication or user interaction is required. The attack is network-based and can be performed remotely. The vulnerability is expected to be used in mass-exploit campaigns targeting thousands of websites.

Impact

Successful exploitation allows an attacker to directly interact with the database, potentially leading to data theft, modification, or deletion [1]. The impact includes information disclosure and possible compromise of the entire WordPress installation.

Mitigation

The vulnerability is fixed in version 2.11.1 [1]. Users should update to version 2.11.1 or later immediately. Patchstack has issued a mitigation rule to block attacks until the update is applied. No workarounds are provided other than updating.

AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.