CVE-2026-92099
WPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration and Alias Squatting
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them.
| Vendor | unknown |
| Product | wpgraphql smart cache |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wpgraphql smart cache
Be the first to know when new unknown vulnerabilities affecting unknown wpgraphql smart cache are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WPGraphQL Smart Cache
0 < 2.3.2
References
Credits
msfire WPScan