Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wordpress poll vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2013-1400
Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow malicious users to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.
Cardozatechnologies Wordpress Poll 34.05
Cardozatechnologies Wordpress Poll 34.06
9.8
CVSSv3
CVE-2013-1401
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote malicious user to add, edit, and delete an answer and delete a poll.
Cardozatechnologies Wordpress Poll 34.05
6.1
CVSSv3
CVE-2016-10936
The wp-polls plugin prior to 2.73.1 for WordPress has XSS via the Poll bar option.
Wp-polls Project Wp-polls
8.8
CVSSv3
CVE-2017-18521
The democracy-poll plugin prior to 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.
Wp-kama Democracy Poll
6.1
CVSSv3
CVE-2017-18520
The democracy-poll plugin prior to 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.
Wp-kama Democracy Poll
6.1
CVSSv3
CVE-2019-9914
The yop-poll plugin prior to 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
Yop-poll Yop-poll
6.5
CVSSv3
CVE-2019-9568
The "Forminator Contact Form, Poll & Quiz Builder" plugin prior to 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
Incsub Forminator
6.1
CVSSv3
CVE-2019-9567
The "Forminator Contact Form, Poll & Quiz Builder" plugin prior to 1.6 for WordPress has XSS via a custom input field of a poll.
Incsub Forminator
NA
CVE-2015-2090
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote malicious users to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.
Sympies Wordpress Survey And Poll 1.1.7
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3