plugin

Polldaddy Vulnerabilities

24 known security issues reported for the Polldaddy WordPress plugin. Most recent disclosed Nov 19, 2024.

1 high 8 medium

Running Polldaddy on your site? Check whether your installed version is affected.

Scan your site free

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] <= 3.1.2 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Cross Site Request Forgery.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.1.2.

Affected:
up to 3.1.2
Fix:
No patched version reported
Disclosed:
Nov 19, 2024

CVE-2024-43338 on NVD →

Crowdsignal Dashboard – Polls, Surveys & more <= 3.1.3 - Cross-Site Request Forgery

medium

The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a for...

CVSS:
4.3
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Sep 24, 2024

CVE-2024-43338 on NVD →

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 3.1.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Mar 16, 2024

CVE-2023-51489 on NVD →

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 3.1.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.

Affected:
up to 3.1.0
Fixed in:
3.1.0
Disclosed:
Feb 10, 2024

CVE-2023-51488 on NVD →

Crowdsignal Dashboard – Polls, Surveys & more <= 3.0.11 - Reflected Cross-Site Scripting

medium

The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 3.0.11
Fixed in:
3.1.0
Disclosed:
Dec 27, 2023

CVE-2023-51488 on NVD →

Crowdsignal Dashboard – Polls, Surveys & more <= 3.0.11 - Cross-Site Request Forgery via update_rating

medium

The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.11. This is due to missing or incorrect nonce validation on the update_rating function. This makes it possible for unauthenticated attackers to update ratings via a fo...

CVSS:
4.3
Affected:
up to 3.0.11
Fixed in:
3.1.0
Disclosed:
Dec 27, 2023

CVE-2023-51489 on NVD →

Crowdsignal Dashboard <= 3.0.9 - Authorization Bypass

medium

The Crowdsignal Dashboard plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 3.0.9. This is due to missing authorization checks on the settings page that made it possible for contributor-level attackers to load the ratings settings page and modify the settings.

CVSS:
5.4
Affected:
up to 3.0.9
Fixed in:
3.0.10
Disclosed:
Nov 17, 2022

CVE-2022-45069 on NVD →

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 3.0.10

unknown

[en] Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.

Affected:
up to 3.0.10
Fixed in:
3.0.10
Disclosed:
Nov 17, 2022

CVE-2022-45069 on NVD →

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 3.0.8

unknown

[en] The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

Affected:
up to 3.0.8
Fixed in:
3.0.8
Disclosed:
Aug 8, 2022

CVE-2022-2386 on NVD →

Crowdsignal Dashboard – Polls, Surveys & more <= 3.0.7 - Reflected Cross-Site Scripting

medium

The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mediaType' parameter in versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...

CVSS:
6.1
Affected:
up to 3.0.7
Fixed in:
3.0.8
Disclosed:
Jul 18, 2022

CVE-2022-2386 on NVD →

Crowdsignal Dashboard – Polls, Surveys & more <= 2.0.31 - Stored Cross-Site scripting

medium

The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll content in versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

CVSS:
6.4
Affected:
up to 2.0.31
Fixed in:
2.0.32
Disclosed:
May 26, 2016

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.32

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Upgrade this plugin.

Affected:
up to 2.0.32
Fixed in:
2.0.32
Disclosed:
May 26, 2016

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.32

unknown

The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll content in versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

Affected:
up to 2.0.32
Fixed in:
2.0.32
Disclosed:
May 26, 2016

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.24

unknown

This plugin is prone to a reflected cross site scripting vulnerability in polldaddy-org.php polldaddy-ratings-title-filter parameter. Upgrade the plugin.

Affected:
up to 2.0.24
Fixed in:
2.0.24
Disclosed:
May 15, 2015

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.21

unknown

This plugin is prone to a cross site request forgery vulnerability. Upgrade the plugin.

Affected:
up to 2.0.21
Fixed in:
2.0.21
Disclosed:
May 15, 2015

Crowdsignal Dashboard <= 2.0.24 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a ratings shortcode and a unique ID.

CVSS:
6.1
Affected:
up to 2.0.24
Fixed in:
2.0.25
Disclosed:
Aug 1, 2014

CVE-2014-4856 on NVD →

Polldaddy Polls & Rating < 2.0.24 - Reflected Cross-Site Scripting

medium

The Polldaddy Polls & Rating for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘polldaddy-ratings-title-filter’ parameter in versions up to, and including, 2.0.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

CVSS:
6.1
Affected:
up to 2.0.24
Fixed in:
2.0.24
Disclosed:
Aug 1, 2014

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.24

unknown

The Polldaddy Polls & Rating for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘polldaddy-ratings-title-filter’ parameter in versions up to, and including, 2.0.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...

Affected:
up to 2.0.24
Fixed in:
2.0.24
Disclosed:
Aug 1, 2014

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.25

unknown

[en] Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a ratings shortcode and a unique ID. NOTE: some of these details are obtained from third party information.

Affected:
up to 2.0.25
Fixed in:
2.0.25
Disclosed:
Jul 10, 2014

CVE-2014-4856 on NVD →

Crowdsignal Dashboard < 2.0.21 - Cross-Site Request Forgery

high

The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.0.21. This is due to missing or incorrect nonce validation in the rating_settings function. This makes it possible for unauthenticated attackers to have an unknown impact via a forged...

CVSS:
7.1
Affected:
up to 2.0.21
Fixed in:
2.0.21
Disclosed:
Nov 6, 2013

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.21

unknown

The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.0.21. This is due to missing or incorrect nonce validation in the rating_settings function. This makes it possible for unauthenticated attackers to have an unknown impact via a forged...

Affected:
up to 2.0.21
Fixed in:
2.0.21
Disclosed:
Nov 6, 2013

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.32

unknown

Similar issue to the one in Jetpack&#039;s Polldaddy module.

Affected:
up to 2.0.32
Fixed in:
2.0.32

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.24

unknown

The Crowdsignal Polls &amp; Ratings WordPress plugin was affected by a polldaddy-org.php polldaddy-ratings-title-filter Parameter Reflected XSS security vulnerability.

Affected:
up to 2.0.24
Fixed in:
2.0.24

Crowdsignal Dashboard &#8211; Polls, Surveys &amp; more [polldaddy] < 2.0.21

unknown

The Crowdsignal Polls &amp; Ratings WordPress plugin was affected by a Cross-Site Request Forgery security vulnerability.

Affected:
up to 2.0.21
Fixed in:
2.0.21

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database