CVE-2026-88974: 
PHP 취약성 분석 및 완화

개요

CVE-2026-88974 is an incorrect authorization vulnerability in the WPGraphQL WordPress plugin that allows an authenticated Contributor to publish their own draft posts without the required publish_posts capability and to modify previously published posts despite lacking edit_published_posts. The flaw exists in the updatePost GraphQL mutation and affects all WPGraphQL versions prior to 2.22.2; version 2.19.0 is confirmed affected. The advisory was published on September 4, 2026, and assigned a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory, WPGraphQL Advisory).

기술적 세부 사항

The root cause is CWE-863 (Incorrect Authorization): src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and post authorship, but omits two critical object-level checks that WordPress's own REST API enforces — current_user_can( $post_type_object->cap->edit_post, $post_id ) and current_user_can( $post_type_object->cap->publish_posts ) for public status transitions. The mutation passes the requested status directly to wp_update_post(), which assumes the caller has already enforced authorization. By contrast, WPGraphQL's createPost implementation correctly downgrades unauthorized publish attempts to pending; this protection was simply absent from updatePost. Exploitation requires only a valid Contributor account and network access to the /graphql endpoint, authenticatable via Application Password or session cookie (WPGraphQL Advisory, Fix PR #4270).

영향

A compromised or malicious Contributor can bypass the site's editorial approval workflow to publish spam, phishing, misleading, or SEO-manipulation content without Editor or Administrator review, and can alter previously approved published posts — undermining content integrity and potentially availability of those posts. The vulnerability does not expose confidential data, permit modification of other authors' posts, enable role escalation, allow arbitrary code execution, or provide access to secrets; normal WordPress HTML sanitization still applies to submitted content. The primary risk is to site integrity and reputation, with chained attacks possible (e.g., injecting malicious links into published content accessible to all unauthenticated visitors) (WPGraphQL Advisory).

악용 가능성

A proof-of-concept exploit consisting of step-by-step curl commands with concrete GraphQL mutations is publicly documented in the GitHub Security Advisory (WPGraphQL Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting low current exploitation probability. Exploitation is not automatable at scale because it requires a valid authenticated Contributor account on the target WordPress instance (Github Advisory).

착취 단계

  1. Obtain Contributor credentials: Acquire a valid WordPress Contributor account (via compromise, insider access, or self-registration if open) and generate an Application Password, or obtain a valid session cookie with a wp_graphql/wp_rest nonce.
  2. Create a draft post: Send a createPost GraphQL mutation to /graphql to create a draft under the Contributor's account:
curl --user 'gql_contributor:APPLICATION_PASSWORD' \
  -H 'Content-Type: application/json' \
  --data-binary '{"query":"mutation { createPost(input:{title:\"Test\", content:\"Content\", status:DRAFT}) { post { databaseId status } } }"}' \
  'https://wordpress.example/graphql'

Record the returned databaseId (e.g., 21). 3. Confirm REST API blocks publication (optional verification): Attempt to publish via the WordPress REST API to confirm the Contributor lacks publish_posts; expect a 403 rest_cannot_publish response. 4. Exploit updatePost to publish the draft: Send an updatePost mutation with status:PUBLISH — the mutation skips the required capability checks and publishes the post:

curl --user 'gql_contributor:APPLICATION_PASSWORD' \
  -H 'Content-Type: application/json' \
  --data-binary '{"query":"mutation { updatePost(input:{id:\"21\", status:PUBLISH}) { post { databaseId status uri } } }"}' \
  'https://wordpress.example/graphql'

The response returns status: publish and a public URI. 5. Verify public exposure: Access the returned URI without authentication or query the GraphQL endpoint unauthenticated to confirm the post is publicly visible. 6. Optional — modify previously published posts: Use updatePost with title and content fields targeting a previously published post owned by the Contributor to alter editorially approved content, bypassing the edit_published_posts check that the REST API enforces (WPGraphQL Advisory).

타협의 징후

  • Network: Unexpected POST requests to /graphql from Contributor-level accounts containing updatePost mutations with status:PUBLISH or content modification inputs; GraphQL responses returning status: publish for posts authored by Contributors.
  • Logs: WordPress/web server access logs showing POST requests to /graphql with updatePost and PUBLISH status from Contributor user accounts; absence of corresponding REST API publish attempts (which would be blocked) alongside successful GraphQL publish events.
  • Content/Database: Posts in wp_posts with post_status = 'publish' authored by Contributor-role users that were not approved through the standard editorial workflow; unexpected changes to titles or content of previously published posts owned by Contributors.
  • Application: GraphQL query logs (if enabled via WPGraphQL debug/logging) showing updatePost mutations with status:PUBLISH or content changes from accounts lacking publish_posts or edit_published_posts capabilities (WPGraphQL Advisory).

완화 및 해결 방법

Update WPGraphQL to version 2.22.2 or later, which adds object-level edit_post capability enforcement and publish_posts checks to the updatePost mutation, mirroring WordPress REST API behavior (WPGraphQL Release, Fix PR #4270). No configuration-based workaround is available; upgrading is the only remediation. After patching, administrators should audit posts published or modified by Contributor-role accounts since the initial deployment of affected versions to identify any unauthorized content changes (Github Advisory).

추가 자료


근원: 이 보고서는 AI를 사용하여 생성되었습니다.

관련 PHP 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-91768MEDIUM6.5
  • PHP logoPHP
  • php:7.4::php-common
아니요예Sep 25, 2026
CVE-2026-91767MEDIUM6.5
  • PHP logoPHP
  • php-opcache
아니요예Sep 25, 2026
CVE-2026-92842MEDIUM5.9
  • PHP logoPHP
  • php:8.2::php-process
아니요예Sep 25, 2026
CVE-2026-91766MEDIUM5.9
  • PHP logoPHP
  • php8.4-fpm
아니요예Sep 25, 2026
CVE-2026-91769MEDIUM4.3
  • PHP logoPHP
  • php-fpm
아니요예Sep 25, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자