Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
yop-poll yop poll vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-1600
The YOP Poll WordPress plugin prior to 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
Yop-poll Yop Poll
312
VMScore
CVE-2022-0205
The YOP Poll WordPress plugin prior to 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue
Yop-poll Yop-poll
312
VMScore
CVE-2017-2127
Cross-site scripting vulnerability in YOP Poll versions before 5.8.1 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Yop-poll Yop Poll
383
VMScore
CVE-2021-24454
In the YOP Poll WordPress plugin prior to 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' ...
Yop-poll Yop Poll
383
VMScore
CVE-2019-9914
The yop-poll plugin prior to 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
Yop-poll Yop-poll
312
VMScore
CVE-2021-24833
The YOP Poll WordPress plugin prior to 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vuln...
Yop-poll Yop Poll
383
VMScore
CVE-2021-24885
The YOP Poll WordPress plugin prior to 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
Yop-poll Yop-poll
383
VMScore
CVE-2021-24834
The YOP Poll WordPress plugin prior to 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. Th...
Yop-poll Yop Poll
NA
CVE-2023-6109
The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated malicious users to place multiple votes on a single poll even w...
Yop-poll Yop Poll
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started