Moderate severityNVD Advisory· Published Jul 31, 2026· Updated Aug 3, 2026
WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)
CVE-2026-54768
Description
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wp-graphql/wp-graphqlPackagist | <= 2.6.0 | — |
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-jhh7-832h-f8hvghsaADVISORY
- github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql/v2.15.1ghsax_refsource_MISCWEB
- github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hvghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.