Poll Maker <= 3.4 - Authenticated (Subscriber+) Arbitrary File Upload
critical
The WP Poll Maker – Best WordPress Poll Plugin for Voting Contest plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 3.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary fi...
- CVSS:
- 9.9
- Affected:
- up to 3.4
- Fixed in:
- 3.5
- Disclosed:
- Apr 15, 2024
CVE-2024-32514 on NVD →
WP Poll Maker <= 3.1 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The WP Poll Maker – Best WordPress Poll Plugin for Voting Contest plugin for WordPress is vulnerable to arbitrary file deletion due to a missing capability check on the it_epoll_theme_action_uninstall() function and insufficient file path validation in all versions up to, and including, 3.1. This makes it possible for...
- CVSS:
- 8.8
- Affected:
- up to 3.1
- Fixed in:
- 3.4
- Disclosed:
- Apr 5, 2024
CVE-2024-31240 on NVD →
WP Poll Maker <= 3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
medium
The WP Poll Maker – Best WordPress Poll Plugin for Voting Contest plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 4.4
- Affected:
- up to 3.1
- Fixed in:
- 3.4
- Disclosed:
- Mar 25, 2024
CVE-2024-29818 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database