vendor:
WordPress Plugin WPGraphQL
by:
Dolev Farhi
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: WordPress Plugin WPGraphQL
Affected Version From: 1.3.5
Affected Version To: 1.3.5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu
2021
WordPress Plugin WPGraphQL 1.3.5 – Denial of Service
This attack uses duplication of fields amplified by GraphQL batched queries, resulting in server OOM and MySQL connection errors.
Mitigation:
Ensure that the WordPress Plugin WPGraphQL is up to date and patched to the latest version.