Skip to main content
Vulnerability Database/CVE-2026-92099

CVE-2026-92099: WPGraphQL Smart Cache Auth Bypass Flaw

CVE-2026-92099 is an authentication bypass vulnerability in the WPGraphQL Smart Cache WordPress plugin that lets unauthenticated users publish arbitrary query documents. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-92099 Overview

CVE-2026-92099 affects the WPGraphQL Smart Cache WordPress plugin before version 2.3.2. The plugin fails to require authorization or validate caller-supplied query identifiers before storing persisted queries from incoming requests. Unauthenticated attackers can publish arbitrary GraphQL query documents and claim query aliases before a site's own frontend registers them. This weakness is categorized under [CWE-284] Improper Access Control. The flaw enables adversaries to poison the persisted query cache and redirect legitimate alias lookups to attacker-controlled documents.

Critical Impact

Unauthenticated attackers can register arbitrary persisted GraphQL queries and hijack query aliases used by a site's own frontend, corrupting cached query resolution.

Affected Products

  • WPGraphQL Smart Cache WordPress plugin versions prior to 2.3.2
  • WordPress sites exposing the WPGraphQL Smart Cache persisted query endpoint
  • Frontend applications depending on WPGraphQL persisted query aliases

Discovery Timeline

  • 2026-09-19 - CVE-2026-92099 published to the National Vulnerability Database
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-92099

Vulnerability Analysis

WPGraphQL Smart Cache implements persisted queries, a pattern where clients register a GraphQL query document once and reference it later by a short identifier or alias. The affected versions accept persisted query registration requests without verifying the requester's authorization. The plugin also fails to validate that a caller-supplied query identifier belongs to the requester or is unclaimed. An unauthenticated network attacker can submit a crafted request that stores an arbitrary query document under any alias. Legitimate frontend applications that later request the same alias receive the attacker's document instead of their intended query. The impact includes integrity loss on cached GraphQL responses and potential availability degradation for dependent frontends.

Root Cause

The root cause is missing access control on the persisted query storage path. The plugin treats persisted query submission as a public operation and trusts client-supplied identifiers as authoritative. No ownership check, capability check, or first-write-wins collision guard is enforced before writing the record.

Attack Vector

Exploitation requires only network access to the WordPress site's GraphQL endpoint. The attacker sends a persisted query registration request containing a chosen alias and a chosen query document. If the alias is unclaimed, the attacker's document becomes the canonical resolution for that alias. Technical details are described in the WPScan Vulnerability Report.

Exploitation code is not published. The vulnerability mechanism is described in prose above. Refer to the WPScan advisory for validated technical details.

Detection Methods for CVE-2026-92099

Indicators of Compromise

  • Persisted GraphQL query records created by unauthenticated sessions or from unexpected source IP addresses
  • Query aliases resolving to documents that differ from those registered by the site's frontend build pipeline
  • Bursts of POST requests to the WPGraphQL endpoint containing persisted query registration payloads

Detection Strategies

  • Inventory all persisted query aliases stored by WPGraphQL Smart Cache and compare against the expected set produced by the frontend build
  • Enable web server access logging for the GraphQL endpoint and flag registration requests without an authenticated session cookie
  • Alert on GraphQL responses whose query text or field selection deviates from the frontend's known query catalog

Monitoring Recommendations

  • Monitor WordPress database tables and object cache entries used by WPGraphQL Smart Cache for unexpected write activity
  • Review WAF telemetry for anomalous request patterns targeting /graphql with persisted query extensions
  • Correlate plugin version inventory against the 2.3.2 fix threshold across all managed WordPress installations

How to Mitigate CVE-2026-92099

Immediate Actions Required

  • Upgrade WPGraphQL Smart Cache to version 2.3.2 or later on every affected WordPress site
  • Audit the persisted query store and delete any records that cannot be attributed to the site's own frontend deployment
  • Rotate or re-register the frontend's persisted query aliases after cleanup to prevent stale attacker records from being reused

Patch Information

The vendor addressed the missing authorization check in WPGraphQL Smart Cache version 2.3.2. Administrators should update through the WordPress plugin dashboard or by deploying the fixed release from the plugin repository. Confirm the installed version after upgrade to verify remediation.

Workarounds

  • Restrict access to the WordPress GraphQL endpoint at the web server or WAF layer to authenticated frontend origins only
  • Disable persisted query registration if the deployment does not depend on it, and pre-populate the store from a trusted build pipeline
  • Enforce authentication on the GraphQL endpoint using a reverse proxy or plugin-level access rule until the patch is applied
bash
# Example nginx location block restricting GraphQL to trusted internal origins
location /graphql {
    allow 10.0.0.0/8;
    deny all;
    proxy_pass http://wordpress_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.