Medium 5.4
2026-05-07< 2.5.4
CVE-2025-68604
Minimum safe version
2.11.1
Update to 2.11.1 or later to address 11 fixable vulnerabilities
CVE-2025-68604
WPGraphQL < 2.11.1 - Unauthenticated SQL Injection
WPGraphQL <= 2.9.1 - Missing Authorization
CVE-2026-27938
CVE-2023-23684
WordPress WPGraphQL plugin <= 0.2.3 - Multiple Vulnerabilities
WPGraphQL <= 1.3.5 - Denial of Service
CVE-2019-25060
CVE-2019-9881
CVE-2019-9880
CVE-2019-9879