Description
WordPress Plugin WPGraphQL is prone to a Denial of Service vulnerability. Exploiting this issue may allow an attacker to cause the affected website to consume memory and CPU resources, thus denying service to legitimate users. WordPress Plugin WPGraphQL version 1.3.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.6 or latest
References
https://www.exploit-db.com/exploits/49807
https://sploitus.com/exploit?id=WPEX-ID:95CC88C8-18A3-4937-A6A9-8E80C6E859C5
https://plugins.svn.wordpress.org/wp-graphql/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin BuddyStream Multiple Cross-Site Scripting Vulnerabilities (2.6.2)
WordPress Plugin WooCommerce Customers Manager Multiple Vulnerabilities (26.5)
WordPress Plugin WordPress Social Sharing-Social Warfare Multiple Vulnerabilities (3.5.2)
WordPress Plugin Zingiri Web Shop Multiple Cross-Site Scripting Vulnerabilities (2.4.1)
b2evolution URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-22840)