Medium severityNVD Advisory· Published Jul 31, 2026· Updated Sep 10, 2026
CVE-2026-54768
CVE-2026-54768
Description
WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wp-graphql/wp-graphqlPackagist | <= 2.6.0 | — |
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.