← WordPress Vulnerabilities
WordPress security by component

Gato GraphQL

Gato GraphQL (gatographql) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 8.8.

Plugin slug: gatographql

CVE-2026-62102: Gato GraphQL permits subscriber privilege escalation

Gato GraphQL through 19.2.3 permits privilege escalation by an authenticated Subscriber. The CNA vector requires no user interaction and rates confidentiality, integrity, and availability impact as high. The authoritative export does not identify the GraphQL operation, field, resolver, parameter, capability granted, or final privilege level.

PublishedSep 11, 2026
Known safe version19.2.4
Published vulnerabilities for gatographql
Safe version
Sep 11, 2026 CVE-2026-62102
Gato GraphQL permits subscriber privilege escalation
Gato GraphQL through 19.2.3 permits privilege escalation by an authenticated Subscriber. The CNA vector requires no user interaction and rates confidentiality, integrity, and availability impact as high. The authoritative export does not identify the GraphQL operation, field, resolver, parameter, capability granted, or final privilege level.
19.2.4
CVE8.8
NVDPending