plugin

Poll Maker Vulnerabilities

46 known security issues reported for the Poll Maker WordPress plugin. Most recent disclosed May 28, 2026.

3 high 21 medium

Running Poll Maker on your site? Check whether your installed version is affected.

Scan your site free

Poll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Information Exposure in 'ays_poll_get_user_information' AJAX Action

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 6.3.7. This is due to insufficient access controls on the 'ays_poll_get_user_information' AJAX action, which serializes and returns the complete WP_User object...

CVSS:
4.3
Affected:
up to 6.3.7
Fixed in:
6.3.8
Disclosed:
May 28, 2026

CVE-2026-8995 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 6.0.8

unknown

[en] The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the ‘filterbyauthor’ parameter in all versions up to, and including, 6.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q...

Affected:
up to 6.0.8
Fixed in:
6.0.8
Disclosed:
Nov 13, 2025

CVE-2025-12620 on NVD →

Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 6.0.7 - Authenticated (Administrator+) SQL Injection via `filterbyauthor` Parameter

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the ‘filterbyauthor’ parameter in all versions up to, and including, 6.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

CVSS:
4.9
Affected:
up to 6.0.7
Fixed in:
6.0.8
Disclosed:
Nov 12, 2025

CVE-2025-12620 on NVD →

Poll Maker <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Poll Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 6.0.2
Fixed in:
6.0.3
Disclosed:
Sep 22, 2025

CVE-2025-57954 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.9.0

unknown

[en] The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 5.8.9 via the 'ays_finish_poll' AJAX action. This makes it possible for unauthenticated attackers to retrieve admin email information which is exposed i...

Affected:
up to 5.9.0
Fixed in:
5.9.0
Disclosed:
Aug 16, 2025

CVE-2024-12575 on NVD →

Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.8.9 - Unauthenticated Basic Information Exposure

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 5.8.9 via the 'ays_finish_poll' AJAX action. This makes it possible for unauthenticated attackers to retrieve admin email information which is exposed in the...

CVSS:
5.3
Affected:
up to 5.8.9
Fixed in:
5.9.0
Disclosed:
Aug 15, 2025

CVE-2024-12575 on NVD →

Poll Maker <= 5.7.7 - Unauthenticated Race Condition to Multi-Vote

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to a Race Condition in all versions up to, and including, 5.7.7. This is due to the plugin not properly restricting a user's ability to fill out a poll multiple times.. This makes it possible for unauthenticated attackers to...

CVSS:
5.3
Affected:
up to 5.7.7
Fixed in:
5.7.8
Disclosed:
May 7, 2025

CVE-2025-47545 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.7.8

unknown

[en] Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker allows Leveraging Race Conditions. This issue affects Poll Maker: from n/a through 5.7.7.

Affected:
up to 5.7.8
Fixed in:
5.7.8
Disclosed:
May 7, 2025

CVE-2025-47545 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.5.1

unknown

[en] Missing Authorization vulnerability in Ays Pro Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Poll Maker: from n/a through 5.5.0.

Affected:
up to 5.5.1
Fixed in:
5.5.1
Disclosed:
Apr 17, 2025

CVE-2025-24577 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.5.4

unknown

[en] The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 5.5.4
Fixed in:
5.5.4
Disclosed:
Mar 16, 2025

CVE-2024-13602 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.6.6

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ays-pro Poll Maker allows Blind SQL Injection. This issue affects Poll Maker: from n/a through 5.6.5.

Affected:
up to 5.6.6
Fixed in:
5.6.6
Disclosed:
Feb 25, 2025

CVE-2025-26971 on NVD →

Poll Maker <= 5.6.5 - Authenticated (Administrator+) SQL Injection

medium

The Poll Maker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and ab...

CVSS:
4.9
Affected:
up to 5.6.5
Fixed in:
5.6.6
Disclosed:
Feb 23, 2025

CVE-2025-26971 on NVD →

Poll Maker <= 5.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-...

CVSS:
4.4
Affected:
up to 5.5.3
Fixed in:
5.5.4
Disclosed:
Feb 23, 2025

CVE-2024-13602 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.5.5

unknown

[en] Improper Encoding or Escaping of Output vulnerability in Poll Maker Team Poll Maker. This issue affects Poll Maker: from n/a through n/a.

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
Jan 21, 2025

CVE-2024-56277 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.5.7

unknown

[en] Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 5.5.6.

Affected:
up to 5.5.7
Fixed in:
5.5.7
Disclosed:
Jan 15, 2025

CVE-2024-56295 on NVD →

Poll Maker <= 5.5.6 - Missing Authorization

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
6.5
Affected:
up to 5.5.6
Fixed in:
5.5.7
Disclosed:
Jan 3, 2025

CVE-2024-56295 on NVD →

Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.5.4 - Unauthenticated HTML Injection

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.5.4. This is due to the software not properly sanitizing or escaping data added to polls. This makes it possible for unauthenticated attackers to inject HTML elements.

CVSS:
5.3
Affected:
up to 5.5.4
Fixed in:
5.5.5
Disclosed:
Jan 3, 2025

CVE-2024-56277 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 4.7.2

unknown

[en] Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 4.7.1.

Affected:
up to 4.7.2
Fixed in:
4.7.2
Disclosed:
Jan 2, 2025

CVE-2023-45766 on NVD →

Poll Maker <= 5.5.0 - Missing Authorization

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
6.5
Affected:
up to 5.5.0
Fixed in:
5.5.1
Disclosed:
Dec 15, 2024

CVE-2025-24577 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 4.8.1

unknown

[en] Missing Authorization vulnerability in Poll Maker Team Poll Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through 4.8.0.

Affected:
up to 4.8.1
Fixed in:
4.8.1
Disclosed:
Dec 9, 2024

CVE-2023-50904 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.5.5

unknown

[en] The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on the duplicate_poll() function. This makes it possible for unauthenticated attackers to du...

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
Dec 7, 2024

CVE-2024-12115 on NVD →

Poll Maker <= 5.5.4 - Cross-Site Request Forgery to Poll Duplication

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on the duplicate_poll() function. This makes it possible for unauthenticated attackers to duplica...

CVSS:
4.3
Affected:
up to 5.5.4
Fixed in:
5.5.5
Disclosed:
Dec 6, 2024

CVE-2024-12115 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.4.7

unknown

[en] The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query...

Affected:
up to 5.4.7
Fixed in:
5.4.7
Disclosed:
Nov 9, 2024

CVE-2024-9874 on NVD →

WordPress Poll Maker Plugin <= 5.4.6 - Authenticated (Administrator+) Time-Based SQL Injection

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Th...

CVSS:
4.9
Affected:
up to 5.4.6
Fixed in:
5.4.7
Disclosed:
Nov 8, 2024

CVE-2024-9874 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.4.7

unknown

[en] The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query....

Affected:
up to 5.4.7
Fixed in:
5.4.7
Disclosed:
Oct 26, 2024

CVE-2024-9475 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.4.7

unknown

[en] The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll settings in all versions up to, and including, 5.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...

Affected:
up to 5.4.7
Fixed in:
5.4.7
Disclosed:
Oct 26, 2024

CVE-2024-9462 on NVD →

Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.4.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Poll Settings

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll settings in all versions up to, and including, 5.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l...

CVSS:
5.5
Affected:
up to 5.4.6
Fixed in:
5.4.7
Disclosed:
Oct 25, 2024

CVE-2024-9462 on NVD →

Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.4.6 - Authenticated (Administrator+) SQL Injection via Order_by Parameter

medium

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This...

CVSS:
4.9
Affected:
up to 5.4.6
Fixed in:
5.4.7
Disclosed:
Oct 25, 2024

CVE-2024-9475 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.1.9

unknown

[en] The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_poll_create_author function in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to extract email addresses by enum...

Affected:
up to 5.1.9
Fixed in:
5.1.9
Disclosed:
May 2, 2024

CVE-2024-3601 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 5.1.9

unknown

[en] The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and including, 5.1.8. This makes it possible for...

Affected:
up to 5.1.9
Fixed in:
5.1.9
Disclosed:
Apr 19, 2024

CVE-2024-3600 on NVD →

Poll Maker – Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting

high

The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and including, 5.1.8. This makes it possible for unau...

CVSS:
7.2
Affected:
up to 5.1.8
Fixed in:
5.1.9
Disclosed:
Apr 18, 2024

CVE-2024-3600 on NVD →

Poll Maker – Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Email Enumeration

medium

The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_poll_create_author function in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to extract email addresses by enumerati...

CVSS:
5.3
Affected:
up to 5.1.8
Fixed in:
5.1.9
Disclosed:
Apr 18, 2024

CVE-2024-3601 on NVD →

Poll Maker <= 4.8.0 - Missing Authorization

medium

The Poll Maker plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 4.8.0. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
5.3
Affected:
up to 4.8.0
Fixed in:
4.8.1
Disclosed:
Dec 26, 2023

CVE-2023-50904 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 4.6.3

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue affects Poll Maker – Best WordPress Poll Plugin: from n/a through 4.6.2.

Affected:
up to 4.6.3
Fixed in:
4.6.3
Disclosed:
Nov 13, 2023

CVE-2023-34013 on NVD →

Poll Maker <= 4.7.1 - Missing Authorization

medium

The Poll Maker plugin for WordPress is vulnerable to unauthorized access of data or functionality due to a missing capability check on one of its functions in all versions up to, and including, 4.7.1. This makes it possible for unauthenticated attackers to make use of this function.

CVSS:
5.3
Affected:
up to 4.7.1
Fixed in:
4.7.2
Disclosed:
Oct 12, 2023

CVE-2023-45766 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 4.7.1

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Poll Maker Team Poll Maker plugin <= 4.7.0 versions.

Affected:
up to 4.7.1
Fixed in:
4.7.1
Disclosed:
Sep 25, 2023

CVE-2023-41871 on NVD →

Poll Maker <= 4.7.0 - Reflected Cross-Site Scripting

medium

The Poll Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tric...

CVSS:
6.1
Affected:
up to 4.7.0
Fixed in:
4.7.1
Disclosed:
Sep 5, 2023

CVE-2023-41871 on NVD →

Poll Maker <= 4.6.2 - Authenticated (Admin+) Server-Side Request Forgery

medium

The Poll Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 4.6.2. This makes it possible for authenticated attackers, with administrator-level access, to make web requests to arbitrary locations originating from the web application which can be used to query and m...

CVSS:
4.7
Affected:
up to 4.6.2
Fixed in:
4.6.3
Disclosed:
Jun 26, 2023

CVE-2023-34013 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 4.0.2

unknown

[en] The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
May 30, 2022

CVE-2022-1456 on NVD →

Poll Maker <= 4.0.1 - Admin+ Stored Cross-Site Scripting

medium

The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed

CVSS:
5.5
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
May 4, 2022

CVE-2022-1456 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 3.4.2

unknown

[en] The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.

Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Oct 11, 2021

CVE-2021-24651 on NVD →

Poll Maker < 3.4.2 - Unauthenticated SQL Injection

high

The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.

CVSS:
7.5
Affected:
up to 3.4.2
Fixed in:
3.4.2
Disclosed:
Sep 13, 2021

CVE-2021-24651 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 3.2.9

unknown

[en] The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-maker-settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.8.

Affected:
up to 3.2.9
Fixed in:
3.2.9
Disclosed:
Aug 2, 2021

CVE-2021-34635 on NVD →

Poll Maker &#8211; Versus Polls, Anonymous Polls, Image Polls [poll-maker] < 3.2.1

unknown

[en] The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Aug 2, 2021

CVE-2021-24483 on NVD →

Poll Maker <= 3.2.8 – Reflected Cross-Site Scripting

medium

The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-maker-settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.8.

CVSS:
6.1
Affected:
up to 3.2.8
Fixed in:
3.2.9
Disclosed:
Jul 26, 2021

CVE-2021-34635 on NVD →

Poll Maker <= 3.2.0 - SQL Injection

high

The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVSS:
7.2
Affected:
up to 3.2.1
Fixed in:
3.2.1
Disclosed:
Jun 29, 2021

CVE-2021-24483 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database