Junglewise Threat Intelligence

CVE-2026-62102: Gato GraphQL privilege escalation in WordPress plugin

CVE-2026-62102 · Severity: high · CVSS 8.8 · Published 2026-09-11

Executive brief

Gato GraphQL is a popular WordPress plugin that provides GraphQL API functionality to WordPress sites. The vulnerability allows low-privilege subscriber accounts to escalate their permissions and gain full administrative control over the entire WordPress installation, potentially compromising site content, user data, and operations.

Technical details

This is a privilege escalation vulnerability (OWASP A7: Identification and Authentication Failures) affecting Gato GraphQL WordPress plugin versions 19.2.3 and earlier. The vulnerability allows an authenticated user with subscriber-level privileges to escalate to administrator role without proper authorization checks. The attack is network-reachable and requires only valid subscriber account credentials. An attacker can exploit this to gain full administrative control over the WordPress installation. The vulnerability was patched in version 19.2.4.

Affected products

  • Gato GraphQL Gato GraphQL <= 19.2.3

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: patched in version 19.2.4
  • 2026-08-30: other: reported by benzdeus

References