๐Ÿ” CVE Alert

CVE-2026-92099

UNKNOWN 0.0

WPGraphQL Smart Cache < 2.3.2 - Unauthenticated Persisted Query Registration and Alias Squatting

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not require authorisation or validate a caller-supplied query identifier before storing a persisted query from a request, allowing unauthenticated users to publish arbitrary query documents and claim query aliases before a site's own frontend registers them.

Vendor unknown
Product wpgraphql smart cache
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wpgraphql smart cache

Be the first to know when new unknown vulnerabilities affecting unknown wpgraphql smart cache are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WPGraphQL Smart Cache
0 < 2.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/3563529f-5050-4f92-9a3c-44ee850254bd/

Credits

msfire WPScan