WordPress Poll [cardoza-wordpress-poll] < 37 (unfixed + closed)
unknown
Authenticated SQL Injection (SQLi) vulnerability found by zerodetail & ratherbland in WordPress Cardoza Poll plugin (versions <= 36).
- Affected:
- up to 37
- Fix:
- No patched version reported
- Disclosed:
- Aug 27, 2020
WordPress Poll <= 36 - SQL Injection
high
The Poll Plugin for WordPress is vulnerable to blind SQL Injection via the 'pollid' parameter in versions up to, and including, 36 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append add...
- CVSS:
- 7.2
- Affected:
- up to 36
- Fix:
- No patched version reported
- Disclosed:
- Aug 26, 2020
CVE-2020-24315 on NVD →
WordPress Poll [cardoza-wordpress-poll] <= 36
unknown
[en] Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.
- Affected:
- up to 36
- Fixed in:
- 36
- Disclosed:
- Aug 26, 2020
CVE-2020-24315 on NVD →
WordPress Poll [cardoza-wordpress-poll] < 34.06 (closed)
unknown
[en] Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.
- Affected:
- up to 34.06
- Fixed in:
- 34.06
- Disclosed:
- Feb 13, 2020
CVE-2013-1400 on NVD →
WordPress Poll [cardoza-wordpress-poll] < 34.06 (closed)
unknown
[en] Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.
- Affected:
- up to 34.06
- Fixed in:
- 34.06
- Disclosed:
- Feb 13, 2020
CVE-2013-1401 on NVD →
WordPress Poll [cardoza-wordpress-poll] < 33.6 (closed)
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Update the plugin.
- Affected:
- up to 33.6
- Fixed in:
- 33.6
- Disclosed:
- May 15, 2015
WordPress Poll <= 34.05 - SQL Injection
critical
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.05 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.
- CVSS:
- 9.8
- Affected:
- up to 34.05
- Fixed in:
- 34.06
- Disclosed:
- Jan 21, 2013
CVE-2013-1401 on NVD →
WordPress Poll < 34.06 - SQL Injection
critical
Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.
- CVSS:
- 9.8
- Affected:
- up to 34.05
- Fixed in:
- 34.06
- Disclosed:
- Jan 21, 2013
CVE-2013-1400 on NVD →
WordPress Poll [cardoza-wordpress-poll] < 33.6 (closed)
unknown
- Affected:
- up to 33.6
- Fixed in:
- 33.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database