plugin

Poll Wp Vulnerabilities

15 known security issues reported for the Poll Wp WordPress plugin. Most recent disclosed Feb 19, 2026.

1 critical 1 high 5 medium

Running Poll Wp on your site? Check whether your installed version is affected.

Scan your site free

TS Poll &#8211; Survey, Versus Poll, Image Poll, Video Poll [poll-wp] <= 2.5.5 (unfixed)

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in totalsoft TS Poll poll-wp allows Server Side Request Forgery.This issue affects TS Poll: from n/a through <= 2.5.5.

Affected:
up to 2.5.5
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25428 on NVD →

TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.5.5 - Authenticated (Editor+) Server-Side Request Forgery

medium

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5.5. This makes it possible for authenticated attackers, with Editor-level access and above, to make web requests to arbitrary locations originating from th...

CVSS:
5.5
Affected:
up to 2.5.5
Fixed in:
2.6.0
Disclosed:
Jan 27, 2026

CVE-2026-25428 on NVD →

TS Poll &#8211; Survey, Versus Poll, Image Poll, Video Poll [poll-wp] <= 2.5.3 (unfixed)

unknown

[en] Missing Authorization vulnerability in totalsoft TS Poll poll-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TS Poll: from n/a through <= 2.5.3.

Affected:
up to 2.5.3
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68588 on NVD →

TS Poll <= 2.5.5 - Missing Authorization

medium

The TS Poll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.5.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.5.5
Fixed in:
2.6.0
Disclosed:
Dec 22, 2025

CVE-2025-68588 on NVD →

TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.6 - Authenticated (Administrator+) SQL Injection via 's' Parameter

medium

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the s parameter in all versions up to, and including, 2.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

CVSS:
4.9
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Apr 14, 2025

CVE-2025-3470 on NVD →

TS Poll &#8211; Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 2.4.0

unknown

[en] The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

Affected:
up to 2.4.0
Fixed in:
2.4.0
Disclosed:
Oct 21, 2024

CVE-2024-8625 on NVD →

TS Poll &#8211; Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 2.4.1

unknown

[en] The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...

Affected:
up to 2.4.1
Fixed in:
2.4.1
Disclosed:
Oct 10, 2024

CVE-2024-9022 on NVD →

TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parameter

high

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...

CVSS:
7.2
Affected:
up to 2.4.0
Fixed in:
2.4.1
Disclosed:
Oct 9, 2024

CVE-2024-9022 on NVD →

TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.3.9 - Authenticated (Admin+) SQL Injection

medium

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...

CVSS:
4.9
Affected:
up to 2.3.9
Fixed in:
2.4.0
Disclosed:
Sep 30, 2024

CVE-2024-8625 on NVD →

TS Poll – Best Poll Plugin for WordPress <= 1.5.8 - Reflected Cross-Site Scripting

medium

The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘nonce’ parameter in versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

CVSS:
6.1
Affected:
up to 1.5.8
Fixed in:
1.5.9
Disclosed:
Aug 25, 2021

TS Poll &#8211; Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 1.5.9

unknown

The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘nonce’ parameter in versions up to, and including, 1.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...

Affected:
up to 1.5.9
Fixed in:
1.5.9
Disclosed:
Aug 25, 2021

TS Poll – Best Poll Plugin for WordPress <1.3.4 - Missing Authorization

critical

The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'wp_ajax_nopriv' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to to manipulate polls, e.g., delete, clone, or view a...

CVSS:
9.8
Affected:
up to 1.3.4
Fixed in:
1.3.4
Disclosed:
Apr 13, 2020

CVE-2020-11673 on NVD →

TS Poll &#8211; Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 1.3.4

unknown

[en] An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php for sensitive operations.

Affected:
up to 1.3.4
Fixed in:
1.3.4
Disclosed:
Apr 13, 2020

CVE-2020-11673 on NVD →

TS Poll &#8211; Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 1.5.9

unknown

The TotalSoftPoll_1_Vote AJAX action (available to both unauthenticated and unauthenticated users) outputs the invalid nonce without escaping it first, leading to a Reflected Cross-Site Scripting issue. The issue was fixed in 1.5.5, however additional sanitisation and escaping was done in 1.5.5 to 1.5.9

Affected:
up to 1.5.9
Fixed in:
1.5.9

TS Poll &#8211; Survey, Versus Poll, Image Poll, Video Poll [poll-wp] < 2.4.7

unknown
Affected:
up to 2.4.7
Fixed in:
2.4.7

CVE-2025-3470 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database