WordPress Plugin Vulnerabilities

WPGraphQL Smart Cache < 2.0.1 - Unauthenticated Private Content Disclosure

Description

The plugin incorrectly cache authenticated user data (such as draft posts, private content, or other permission-restricted data), which could allow unauthenticated users to then access it

Proof of Concept

Affects Plugins

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Verified
Yes

Timeline

Publicly Published
2025-12-12 (about 2 months ago)
Added
2025-12-12 (about 2 months ago)
Last Updated
2025-12-12 (about 2 months ago)

Other