plugin

Cardoza Wordpress Poll Vulnerabilities

9 known security issues reported for the Cardoza Wordpress Poll WordPress plugin. Most recent disclosed Aug 27, 2020.

2 critical 1 high

Running Cardoza Wordpress Poll on your site? Check whether your installed version is affected.

Scan your site free

WordPress Poll [cardoza-wordpress-poll] < 37 (unfixed + closed)

unknown

Authenticated SQL Injection (SQLi) vulnerability found by zerodetail & ratherbland in WordPress Cardoza Poll plugin (versions <= 36).

Affected:
up to 37
Fix:
No patched version reported
Disclosed:
Aug 27, 2020

WordPress Poll <= 36 - SQL Injection

high

The Poll Plugin for WordPress is vulnerable to blind SQL Injection via the 'pollid' parameter in versions up to, and including, 36 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append add...

CVSS:
7.2
Affected:
up to 36
Fix:
No patched version reported
Disclosed:
Aug 26, 2020

CVE-2020-24315 on NVD →

WordPress Poll [cardoza-wordpress-poll] <= 36

unknown

[en] Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.

Affected:
up to 36
Fixed in:
36
Disclosed:
Aug 26, 2020

CVE-2020-24315 on NVD →

WordPress Poll [cardoza-wordpress-poll] < 34.06 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.

Affected:
up to 34.06
Fixed in:
34.06
Disclosed:
Feb 13, 2020

CVE-2013-1400 on NVD →

WordPress Poll [cardoza-wordpress-poll] < 34.06 (closed)

unknown

[en] Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.

Affected:
up to 34.06
Fixed in:
34.06
Disclosed:
Feb 13, 2020

CVE-2013-1401 on NVD →

WordPress Poll [cardoza-wordpress-poll] < 33.6 (closed)

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Update the plugin.

Affected:
up to 33.6
Fixed in:
33.6
Disclosed:
May 15, 2015

WordPress Poll <= 34.05 - SQL Injection

critical

Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.05 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.

CVSS:
9.8
Affected:
up to 34.05
Fixed in:
34.06
Disclosed:
Jan 21, 2013

CVE-2013-1401 on NVD →

WordPress Poll < 34.06 - SQL Injection

critical

Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.

CVSS:
9.8
Affected:
up to 34.05
Fixed in:
34.06
Disclosed:
Jan 21, 2013

CVE-2013-1400 on NVD →

WordPress Poll [cardoza-wordpress-poll] < 33.6 (closed)

unknown
Affected:
up to 33.6
Fixed in:
33.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database