Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress poll vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2020-24315
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.
Wordpress Poll Project Wordpress Poll
7.5
CVSSv2
CVE-2013-1400
Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow malicious users to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.
Cardozatechnologies Wordpress Poll 34.05
Cardozatechnologies Wordpress Poll 34.06
7.5
CVSSv2
CVE-2013-1401
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote malicious user to add, edit, and delete an answer and delete a poll.
Cardozatechnologies Wordpress Poll 34.05
7.5
CVSSv2
CVE-2015-2090
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote malicious users to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.
Sympies Wordpress Survey And Poll 1.1.7
1 EDB exploit
4.3
CVSSv2
CVE-2019-9914
The yop-poll plugin prior to 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
Yop-poll Yop-poll
4.3
CVSSv2
CVE-2021-24885
The YOP Poll WordPress plugin prior to 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
Yop-poll Yop-poll
NA
CVE-2022-1600
The YOP Poll WordPress plugin prior to 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
Yop-poll Yop Poll
3.5
CVSSv2
CVE-2022-0205
The YOP Poll WordPress plugin prior to 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue
Yop-poll Yop-poll
NA
CVE-2023-6109
The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated malicious users to place multiple votes on a single poll even w...
Yop-poll Yop Poll
3.5
CVSSv2
CVE-2021-24833
The YOP Poll WordPress plugin prior to 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vuln...
Yop-poll Yop Poll
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4040
privilege escalation
CVE-2024-4112
CVE-2024-32872
man-in-the-middle
CVE-2024-32788
bypass
CVE-2024-3400
CVE-2024-28976
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »