CVE-2026-33290 | wp-graphql up to 2.9.x on WordPress CommentUpdate.php moderate_comments user_id authorization (GHSA-9hc3-mh5h-4fgh)
A vulnerability was found in wp-graphql up to 2.9.x on WordPress. It has been declared as problematic. Affected is the function moderate_comments of the file plugins/wp-graphql/src/Mutation/CommentUpdate.php. Executing a manipulation of the argument user_id can lead to missing authorization.
This vulnerability is tracked as CVE-2026-33290. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.