Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress poll vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2021-24834
The YOP Poll WordPress plugin prior to 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. Th...
Yop-poll Yop Poll
4.3
CVSSv2
CVE-2021-24454
In the YOP Poll WordPress plugin prior to 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' ...
Yop-poll Yop Poll
NA
CVE-2023-34013
Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue affects Poll Maker – Best WordPress Poll Plugin: from n/a up to and including 4.6.2.
Ays-pro Poll Maker
4.3
CVSSv2
CVE-2017-18520
The democracy-poll plugin prior to 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.
Wp-kama Democracy Poll
6.8
CVSSv2
CVE-2017-18521
The democracy-poll plugin prior to 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.
Wp-kama Democracy Poll
3.5
CVSSv2
CVE-2022-1456
The Poll Maker WordPress plugin prior to 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed
Ays-pro Poll Maker
4.3
CVSSv2
CVE-2021-34635
The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-maker-settings.php file which allows malicious users to inject arbitrary web scripts, in versions up to and including 3.2.8.
Ays-pro Poll Maker
5
CVSSv2
CVE-2021-24651
The Poll Maker WordPress plugin prior to 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.
Ays-pro Poll Maker
6.5
CVSSv2
CVE-2021-24483
The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin prior to 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in ...
Ays-pro Poll Maker
7.5
CVSSv2
CVE-2020-11673
An issue exists in the Responsive Poll up to and including 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php...
Total-soft Responsive Poll
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »