Description
WordPress Plugin WPGraphQL is prone to a Denial of Service vulnerability. Exploiting this issue may allow an attacker to cause the affected website to consume memory and CPU resources, thus denying service to legitimate users. WordPress Plugin WPGraphQL version 1.3.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.6 or latest
References
https://www.exploit-db.com/exploits/49807
https://sploitus.com/exploit?id=WPEX-ID:95CC88C8-18A3-4937-A6A9-8E80C6E859C5
https://plugins.svn.wordpress.org/wp-graphql/trunk/readme.txt
Related Vulnerabilities
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2146)
WordPress Plugin All-in-One WP Migration Information Disclosure (7.0)
WordPress Plugin Sina Extension for Elementor Multiple Cross-Site Scripting Vulnerabilities (3.3.11)
WordPress Plugin ThemeREX Addons Remote Code Execution (All)
WordPress Plugin Livefyre Comments 3 Cross-Site Scripting (4.1.4)