Executive brief
Gato GraphQL is a popular WordPress plugin that provides GraphQL API functionality to WordPress sites. The vulnerability allows low-privilege subscriber accounts to escalate their permissions and gain full administrative control over the entire WordPress installation, potentially compromising site content, user data, and operations.
Technical details
This is a privilege escalation vulnerability (OWASP A7: Identification and Authentication Failures) affecting Gato GraphQL WordPress plugin versions 19.2.3 and earlier. The vulnerability allows an authenticated user with subscriber-level privileges to escalate to administrator role without proper authorization checks. The attack is network-reachable and requires only valid subscriber account credentials. An attacker can exploit this to gain full administrative control over the WordPress installation. The vulnerability was patched in version 19.2.4.
Affected products
- Gato GraphQL Gato GraphQL <= 19.2.3
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: patched in version 19.2.4
- 2026-08-30: other: reported by benzdeus