plugin

Cp Polls Vulnerabilities

23 known security issues reported for the Cp Polls WordPress plugin. Most recent disclosed Jun 15, 2026.

1 high 10 medium

Running Cp Polls on your site? Check whether your installed version is affected.

Scan your site free

Polls CP <= 1.0.8 - Cross-Site Request Forgery to Cross-Site Scripting

medium

The Polls CP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request gra...

CVSS:
5.4
Affected:
up to 1.0.8
Fixed in:
1.0.9
Disclosed:
Jun 15, 2026

CVE-2016-20066 on NVD →

Polls CP <= 1.0.8 - Cross-Site Request Forgery

medium

The Polls CP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a...

CVSS:
4.3
Affected:
up to 1.0.8
Fixed in:
1.0.9
Disclosed:
Jun 15, 2026

CVE-2016-20067 on NVD →

Polls CP [cp-polls] <= 1.0.81 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Polls allows Stored XSS. This issue affects CP Polls: from n/a through 1.0.81.

Affected:
up to 1.0.81
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-50025 on NVD →

CP Polls <= 1.0.81 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The CP Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.81 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
4.4
Affected:
up to 1.0.81
Fixed in:
1.0.82
Disclosed:
Jun 19, 2025

CVE-2025-50025 on NVD →

Polls CP [cp-polls] < 1.0.75

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CodePeople CP Polls allows Reflected XSS.This issue affects CP Polls: from n/a through 1.0.74.

Affected:
up to 1.0.75
Fixed in:
1.0.75
Disclosed:
Oct 6, 2024

CVE-2024-47297 on NVD →

CP Polls <= 1.0.74 - Reflected Cross-Site Scripting

medium

The CP Polls plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.0.74 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 1.0.74
Fixed in:
1.0.75
Disclosed:
Sep 24, 2024

CVE-2024-47297 on NVD →

Polls CP <= 1.0.76 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Polls CP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.76 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitra...

CVSS:
4.4
Affected:
up to 1.0.76
Fixed in:
1.0.77
Disclosed:
Sep 1, 2024

CVE-2024-8851 on NVD →

Polls CP <= 1.0.76 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Polls CP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.76 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitra...

CVSS:
4.4
Affected:
up to 1.0.76
Fixed in:
1.0.77
Disclosed:
Sep 1, 2024

CVE-2024-8854 on NVD →

Polls CP [cp-polls] < 1.0.72

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71.

Affected:
up to 1.0.72
Fixed in:
1.0.72
Disclosed:
May 17, 2024

CVE-2024-24874 on NVD →

Polls CP [cp-polls] < 1.0.72

unknown

[en] : Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.

Affected:
up to 1.0.72
Fixed in:
1.0.72
Disclosed:
May 17, 2024

CVE-2024-24873 on NVD →

CP Polls <= 1.0.71 - Unauthenticated Content Injection

medium

The Polls CP plugin for WordPress is vulnerable to content injection in all versions up to, and including, 1.0.71. This is due to insufficient validation on poll answers. This makes it possible for unauthenticated attackers to inject arbitrary content.

CVSS:
5.3
Affected:
up to 1.0.71
Fixed in:
1.0.72
Disclosed:
Feb 5, 2024

CVE-2024-24874 on NVD →

CP Polls <= 1.0.71 - Unauthenticated Poll Limit Bypass

medium

The Polls CP plugin for WordPress is vulnerable to Poll Limit Bypass in all versions up to, and including, 1.0.71. This is due to insufficient controls on on the voting system. This makes it possible for unauthenticated attackers to vote multiple times.

CVSS:
5.3
Affected:
up to 1.0.71
Fixed in:
1.0.72
Disclosed:
Feb 5, 2024

CVE-2024-24873 on NVD →

Polls CP [cp-polls] < 1.0.2

unknown

[en] A vulnerability has been found in codepeople cp-polls Plugin 1.0.1 on WordPress and classified as critical. This vulnerability affects unknown code of the file cp-admin-int-message-list.inc.php. The manipulation of the argument lu leads to sql injection. The attack can be initiated remotely. Upgrading to version 1...

Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Mar 4, 2023

CVE-2014-125091 on NVD →

Polls CP [cp-polls] < 1.0.5

unknown

[en] The cp-polls plugin before 1.0.5 for WordPress has XSS.

Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
Aug 27, 2019

CVE-2015-9346 on NVD →

Polls CP [cp-polls] < 1.0.1

unknown

[en] The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Aug 27, 2019

CVE-2014-10395 on NVD →

Polls CP [cp-polls] < 1.0.9

unknown

There are some multiple vulnerabilities in this plugin, such as XSS, CSRF and file download issue. Because of these vulnerabilities, an attacker can inject malicious payload into a votation, inject malicious HTML or JavaScript codes or attack an administrator. Update the plugin.

Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Mar 1, 2016

Polls CP < 1.0.5 - Cross-Site Scripting

medium

The cp-polls plugin before 1.0.5 for WordPress has XSS via the 'name' parameter.

CVSS:
6.1
Affected:
up to 1.0.5
Fixed in:
1.0.5
Disclosed:
May 20, 2015

CVE-2015-9346 on NVD →

Polls CP <= 1.0.1 - Authenticated SQL Injection

high

The Polls CP plugin for WordPress is vulnerable to SQL Injection via the 'lu' parameter in all versions up to, and including, 1.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers to append addi...

CVSS:
8.8
Affected:
up to 1.0.1
Fixed in:
1.0.2
Disclosed:
Nov 23, 2014

CVE-2014-125091 on NVD →

Polls CP < 1.0.1 - Cross-Site Scripting

medium

The Polls CP plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Nov 20, 2014

CVE-2014-10395 on NVD →

Polls CP [cp-polls] < 1.0.9

unknown

The Polls CP WordPress plugin was affected by a Multiple XSS Vulnerabilities security vulnerability.

Affected:
up to 1.0.9
Fixed in:
1.0.9

Polls CP [cp-polls] < 1.0.9

unknown

The Polls CP WordPress plugin was affected by a Multiple CSRF Vulnerabilities security vulnerability.

Affected:
up to 1.0.9
Fixed in:
1.0.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database