October 1, 2026
Unauthenticated Persistent Query Write & QueryId Hijacking
Welcome back, hackers ๐!

By msfire
1 min read
This is my first CVE that I found in the WPGraphQL ecosystem. The vulnerability allows any unauthenticated user on the internet to write directly into the WordPress database and permanently hijack query aliases used by headless applications.
While auditing the WPGraphQL Smart Cache plugin, I started looking into how the plugin handles incoming requests and saves data. My attention was quickly drawn to the 'graphql_request_data' filter hook. I noticed that this hook was firing on every HTTP GraphQL request, without verifying who was making it. So, the question that gave me my first CVE was:
what would happen if an unauthenticated user forced the application to process a crafted persistent query?
Details
The WPGraphQL Smart Cache WordPress plugin does not perform authentication or capability checks before saving persisted GraphQL queries and registering query aliases. The graphql_request_data filter hook fires on every HTTP GraphQL request including unauthenticated ones, and calls wp_insert_post() with post_status set to publish. This allows unauthenticated remote attackers to create arbitrary published posts in the graphql_document custom post type and permanently hijack queryId aliases used by headless WordPress applications, breaking application functionality for all end users.
Proof of Concept
For those who want to reproduce the issue or see the exact payload, here is the raw unauthenticated HTTP request used to trigger the vulnerability and hijack the 'queryId' :
curl -s -X POST https://victim.example/graphql \
-H "Content-Type: application/json" \
-d '{"query":"{ __typename }","queryId":"homepage-posts"}'curl -s -X POST https://victim.example/graphql \
-H "Content-Type: application/json" \
-d '{"query":"{ __typename }","queryId":"homepage-posts"}'Impact
This is not just a simple arbitrary database write. An unauthenticated attacker can effectively break the entire functionality of a headless application relying on this plugin. This leads to a severe disruption of the service for all end users.