TS Poll – Survey, Versus Poll, Image Poll, Video Poll [poll-wp] <= 2.5.5 (unfixed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in totalsoft TS Poll poll-wp allows Server Side Request Forgery.This issue affects TS Poll: from n/a through <= 2.5.5.
- Affected:
- up to 2.5.5
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25428 on NVD →
TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.5.5 - Authenticated (Editor+) Server-Side Request Forgery
medium
The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.5. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from th...
- CVSS:
- 5.5
- Affected:
- up to 2.5.5
- Fixed in:
- 2.6.0
- Disclosed:
- Jan 27, 2026
CVE-2026-25428 on NVD →
TS Poll – Survey, Versus Poll, Image Poll, Video Poll [poll-wp] <= 2.5.3 (unfixed)
unknown
[en] Missing Authorization vulnerability in totalsoft TS Poll poll-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Poll: from n/a through <= 2.5.3.
- Affected:
- up to 2.5.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 24, 2025
CVE-2025-68588 on NVD →
TS Poll <= 2.5.5 - Missing Authorization
medium
The TS Poll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.5.5
- Fixed in:
- 2.6.0
- Disclosed:
- Dec 22, 2025
CVE-2025-68588 on NVD →
TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.6 - Authenticated (Administrator+) SQL Injection via 's' Parameter
medium
The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...
- CVSS:
- 4.9
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Apr 14, 2025
CVE-2025-3470 on NVD →
TS Poll – Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 2.4.0
unknown
[en] The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.0
- Disclosed:
- Oct 21, 2024
CVE-2024-8625 on NVD →
TS Poll – Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 2.4.1
unknown
[en] The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...
- Affected:
- up to 2.4.1
- Fixed in:
- 2.4.1
- Disclosed:
- Oct 10, 2024
CVE-2024-9022 on NVD →
TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parameter
high
The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...
- CVSS:
- 7.2
- Affected:
- up to 2.4.0
- Fixed in:
- 2.4.1
- Disclosed:
- Oct 9, 2024
CVE-2024-9022 on NVD →
TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.3.9 - Authenticated (Admin+) SQL Injection
medium
The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...
- CVSS:
- 4.9
- Affected:
- up to 2.3.9
- Fixed in:
- 2.4.0
- Disclosed:
- Sep 30, 2024
CVE-2024-8625 on NVD →
TS Poll – Best Poll Plugin for WordPress <= 1.5.8 - Reflected Cross-Site Scripting
medium
The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘nonce’ parameter in versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...
- CVSS:
- 6.1
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.9
- Disclosed:
- Aug 25, 2021
TS Poll – Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 1.5.9
unknown
The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘nonce’ parameter in versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.9
- Disclosed:
- Aug 25, 2021
TS Poll – Best Poll Plugin for WordPress <1.3.4 - Missing Authorization
critical
The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'wp_ajax_nopriv' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to to manipulate polls, e.g., delete, clone, or view a...
- CVSS:
- 9.8
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Apr 13, 2020
CVE-2020-11673 on NVD →
TS Poll – Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 1.3.4
unknown
[en] An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php for sensitive operations.
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Apr 13, 2020
CVE-2020-11673 on NVD →
TS Poll – Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 1.5.9
unknown
The TotalSoftPoll_1_Vote AJAX action (available to both unauthenticated and unauthenticated users) outputs the invalid nonce without escaping it first, leading to a Reflected Cross-Site Scripting issue.
The issue was fixed in 1.5.5, however additional sanitisation and escaping was done in 1.5.5 to 1.5.9
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.9
TS Poll – Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 2.4.7
unknown
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
CVE-2025-3470 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database