Loading market data...
← Back to CVE feed

CVE-2026-54768

UNKNOWN View on NVD ↗

Description

WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.

Published: Jul 31, 2026 23:17 UTC Modified: Jul 31, 2026 23:17 UTC