CVE-2026-88974:
PHP 취약성 분석 및 완화
개요
CVE-2026-88974 is an incorrect authorization vulnerability in the WPGraphQL WordPress plugin that allows an authenticated Contributor to publish their own draft posts without the required publish_posts capability and to modify previously published posts despite lacking edit_published_posts. The flaw exists in the updatePost GraphQL mutation and affects all WPGraphQL versions prior to 2.22.2; version 2.19.0 is confirmed affected. The advisory was published on September 4, 2026, and assigned a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory, WPGraphQL Advisory).
기술적 세부 사항
The root cause is CWE-863 (Incorrect Authorization): src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and post authorship, but omits two critical object-level checks that WordPress's own REST API enforces — current_user_can( $post_type_object->cap->edit_post, $post_id ) and current_user_can( $post_type_object->cap->publish_posts ) for public status transitions. The mutation passes the requested status directly to wp_update_post(), which assumes the caller has already enforced authorization. By contrast, WPGraphQL's createPost implementation correctly downgrades unauthorized publish attempts to pending; this protection was simply absent from updatePost. Exploitation requires only a valid Contributor account and network access to the /graphql endpoint, authenticatable via Application Password or session cookie (WPGraphQL Advisory, Fix PR #4270).
영향
A compromised or malicious Contributor can bypass the site's editorial approval workflow to publish spam, phishing, misleading, or SEO-manipulation content without Editor or Administrator review, and can alter previously approved published posts — undermining content integrity and potentially availability of those posts. The vulnerability does not expose confidential data, permit modification of other authors' posts, enable role escalation, allow arbitrary code execution, or provide access to secrets; normal WordPress HTML sanitization still applies to submitted content. The primary risk is to site integrity and reputation, with chained attacks possible (e.g., injecting malicious links into published content accessible to all unauthenticated visitors) (WPGraphQL Advisory).
악용 가능성
A proof-of-concept exploit consisting of step-by-step curl commands with concrete GraphQL mutations is publicly documented in the GitHub Security Advisory (WPGraphQL Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting low current exploitation probability. Exploitation is not automatable at scale because it requires a valid authenticated Contributor account on the target WordPress instance (Github Advisory).
착취 단계
- Obtain Contributor credentials: Acquire a valid WordPress Contributor account (via compromise, insider access, or self-registration if open) and generate an Application Password, or obtain a valid session cookie with a
wp_graphql/wp_restnonce. - Create a draft post: Send a
createPostGraphQL mutation to/graphqlto create a draft under the Contributor's account:
curl --user 'gql_contributor:APPLICATION_PASSWORD' \
-H 'Content-Type: application/json' \
--data-binary '{"query":"mutation { createPost(input:{title:\"Test\", content:\"Content\", status:DRAFT}) { post { databaseId status } } }"}' \
'https://wordpress.example/graphql'Record the returned databaseId (e.g., 21).
3. Confirm REST API blocks publication (optional verification): Attempt to publish via the WordPress REST API to confirm the Contributor lacks publish_posts; expect a 403 rest_cannot_publish response.
4. Exploit updatePost to publish the draft: Send an updatePost mutation with status:PUBLISH — the mutation skips the required capability checks and publishes the post:
curl --user 'gql_contributor:APPLICATION_PASSWORD' \
-H 'Content-Type: application/json' \
--data-binary '{"query":"mutation { updatePost(input:{id:\"21\", status:PUBLISH}) { post { databaseId status uri } } }"}' \
'https://wordpress.example/graphql'The response returns status: publish and a public URI.
5. Verify public exposure: Access the returned URI without authentication or query the GraphQL endpoint unauthenticated to confirm the post is publicly visible.
6. Optional — modify previously published posts: Use updatePost with title and content fields targeting a previously published post owned by the Contributor to alter editorially approved content, bypassing the edit_published_posts check that the REST API enforces (WPGraphQL Advisory).
타협의 징후
- Network: Unexpected POST requests to
/graphqlfrom Contributor-level accounts containingupdatePostmutations withstatus:PUBLISHor content modification inputs; GraphQL responses returningstatus: publishfor posts authored by Contributors. - Logs: WordPress/web server access logs showing POST requests to
/graphqlwithupdatePostandPUBLISHstatus from Contributor user accounts; absence of corresponding REST API publish attempts (which would be blocked) alongside successful GraphQL publish events. - Content/Database: Posts in
wp_postswithpost_status = 'publish'authored by Contributor-role users that were not approved through the standard editorial workflow; unexpected changes to titles or content of previously published posts owned by Contributors. - Application: GraphQL query logs (if enabled via WPGraphQL debug/logging) showing
updatePostmutations withstatus:PUBLISHor content changes from accounts lackingpublish_postsoredit_published_postscapabilities (WPGraphQL Advisory).
완화 및 해결 방법
Update WPGraphQL to version 2.22.2 or later, which adds object-level edit_post capability enforcement and publish_posts checks to the updatePost mutation, mirroring WordPress REST API behavior (WPGraphQL Release, Fix PR #4270). No configuration-based workaround is available; upgrading is the only remediation. After patching, administrators should audit posts published or modified by Contributor-role accounts since the initial deployment of affected versions to identify any unauthorized content changes (Github Advisory).
추가 자료
근원: 이 보고서는 AI를 사용하여 생성되었습니다.
관련 PHP 취약점:
무료 취약성 평가
클라우드 보안 태세를 벤치마킹합니다
9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.
추가 Wiz 리소스
맞춤형 데모 받기
맞춤형 데모 신청하기
"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."