Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress poll vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2021-24885
The YOP Poll WordPress plugin prior to 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
Yop-poll Yop-poll
6.1
CVSSv3
CVE-2021-34635
The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-maker-settings.php file which allows malicious users to inject arbitrary web scripts, in versions up to and including 3.2.8.
Ays-pro Poll Maker
6.1
CVSSv3
CVE-2021-24454
In the YOP Poll WordPress plugin prior to 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' ...
Yop-poll Yop Poll
6.1
CVSSv3
CVE-2016-10936
The wp-polls plugin prior to 2.73.1 for WordPress has XSS via the Poll bar option.
Wp-polls Project Wp-polls
6.1
CVSSv3
CVE-2017-18520
The democracy-poll plugin prior to 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.
Wp-kama Democracy Poll
6.1
CVSSv3
CVE-2019-9914
The yop-poll plugin prior to 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
Yop-poll Yop-poll
6.1
CVSSv3
CVE-2019-9567
The "Forminator Contact Form, Poll & Quiz Builder" plugin prior to 1.6 for WordPress has XSS via a custom input field of a poll.
Incsub Forminator
5.9
CVSSv3
CVE-2023-4642
The kk Star Ratings WordPress plugin prior to 5.4.6 does not implement atomic operations, allowing one user vote multiple times on a poll due to a Race Condition.
Kamalkhan Kk Star Ratings
5.4
CVSSv3
CVE-2022-0205
The YOP Poll WordPress plugin prior to 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue
Yop-poll Yop-poll
5.4
CVSSv3
CVE-2021-24834
The YOP Poll WordPress plugin prior to 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. Th...
Yop-poll Yop Poll
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »