Description
Your web application's GraphQL implementation accepts non-JSON queries over POST requests, increasing the risk of Cross-Site Request Forgery (CSRF) attacks. The request was sent with Content-Type application/x-www-form-urlencoded and succeeded.
Remediation
Restrict GraphQL queries to JSON-based POST requests to limit the CSRF attack surface.
References
Related Vulnerabilities
WordPress Plugin WP Easy Slideshow Multiple Cross-Site Request Forgery Vulnerabilities (1.0.3)
WordPress Plugin WP EasyPay-Square for WordPress Cross-Site Request Forgery (3.2.0)
WordPress Plugin Product Import Export for WooCommerce Cross-Site Request Forgery (1.7.4)
WordPress Plugin Zero BS WordPress CRM Cross-Site Request Forgery (2.99.9)
WordPress Plugin SEO Redirection-301 Redirect Manager Cross-Site Request Forgery (8.9)