Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] <= 3.1.2 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Cross Site Request Forgery.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.1.2.
- Affected:
- up to 3.1.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 19, 2024
CVE-2024-43338 on NVD →
Crowdsignal Dashboard – Polls, Surveys & more <= 3.1.3 - Cross-Site Request Forgery
medium
The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a for...
- CVSS:
- 4.3
- Affected:
- up to 3.1.3
- Fixed in:
- 3.1.4
- Disclosed:
- Sep 24, 2024
CVE-2024-43338 on NVD →
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 3.1.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Mar 16, 2024
CVE-2023-51489 on NVD →
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 3.1.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.
- Affected:
- up to 3.1.0
- Fixed in:
- 3.1.0
- Disclosed:
- Feb 10, 2024
CVE-2023-51488 on NVD →
Crowdsignal Dashboard – Polls, Surveys & more <= 3.0.11 - Reflected Cross-Site Scripting
medium
The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 3.0.11
- Fixed in:
- 3.1.0
- Disclosed:
- Dec 27, 2023
CVE-2023-51488 on NVD →
Crowdsignal Dashboard – Polls, Surveys & more <= 3.0.11 - Cross-Site Request Forgery via update_rating
medium
The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.11. This is due to missing or incorrect nonce validation on the update_rating function. This makes it possible for unauthenticated attackers to update ratings via a fo...
- CVSS:
- 4.3
- Affected:
- up to 3.0.11
- Fixed in:
- 3.1.0
- Disclosed:
- Dec 27, 2023
CVE-2023-51489 on NVD →
Crowdsignal Dashboard <= 3.0.9 - Authorization Bypass
medium
The Crowdsignal Dashboard plugin for WordPress is vulnerable to Authorization Bypass in versions up to, and including, 3.0.9. This is due to missing authorization checks on the settings page that made it possible for contributor-level attackers to load the ratings settings page and modify the settings.
- CVSS:
- 5.4
- Affected:
- up to 3.0.9
- Fixed in:
- 3.0.10
- Disclosed:
- Nov 17, 2022
CVE-2022-45069 on NVD →
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 3.0.10
unknown
[en] Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
- Affected:
- up to 3.0.10
- Fixed in:
- 3.0.10
- Disclosed:
- Nov 17, 2022
CVE-2022-45069 on NVD →
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 3.0.8
unknown
[en] The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 3.0.8
- Fixed in:
- 3.0.8
- Disclosed:
- Aug 8, 2022
CVE-2022-2386 on NVD →
Crowdsignal Dashboard – Polls, Surveys & more <= 3.0.7 - Reflected Cross-Site Scripting
medium
The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mediaType' parameter in versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrar...
- CVSS:
- 6.1
- Affected:
- up to 3.0.7
- Fixed in:
- 3.0.8
- Disclosed:
- Jul 18, 2022
CVE-2022-2386 on NVD →
Crowdsignal Dashboard – Polls, Surveys & more <= 2.0.31 - Stored Cross-Site scripting
medium
The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll content in versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...
- CVSS:
- 6.4
- Affected:
- up to 2.0.31
- Fixed in:
- 2.0.32
- Disclosed:
- May 26, 2016
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.32
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Upgrade this plugin.
- Affected:
- up to 2.0.32
- Fixed in:
- 2.0.32
- Disclosed:
- May 26, 2016
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.32
unknown
The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via poll content in versions up to, and including, 2.0.31 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...
- Affected:
- up to 2.0.32
- Fixed in:
- 2.0.32
- Disclosed:
- May 26, 2016
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.24
unknown
This plugin is prone to a reflected cross site scripting vulnerability in polldaddy-org.php polldaddy-ratings-title-filter parameter.
Upgrade the plugin.
- Affected:
- up to 2.0.24
- Fixed in:
- 2.0.24
- Disclosed:
- May 15, 2015
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.21
unknown
This plugin is prone to a cross site request forgery vulnerability.
Upgrade the plugin.
- Affected:
- up to 2.0.21
- Fixed in:
- 2.0.21
- Disclosed:
- May 15, 2015
Crowdsignal Dashboard <= 2.0.24 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a ratings shortcode and a unique ID.
- CVSS:
- 6.1
- Affected:
- up to 2.0.24
- Fixed in:
- 2.0.25
- Disclosed:
- Aug 1, 2014
CVE-2014-4856 on NVD →
Polldaddy Polls & Rating < 2.0.24 - Reflected Cross-Site Scripting
medium
The Polldaddy Polls & Rating for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘polldaddy-ratings-title-filter’ parameter in versions up to, and including, 2.0.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 6.1
- Affected:
- up to 2.0.24
- Fixed in:
- 2.0.24
- Disclosed:
- Aug 1, 2014
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.24
unknown
The Polldaddy Polls & Rating for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘polldaddy-ratings-title-filter’ parameter in versions up to, and including, 2.0.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- Affected:
- up to 2.0.24
- Fixed in:
- 2.0.24
- Disclosed:
- Aug 1, 2014
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.25
unknown
[en] Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a ratings shortcode and a unique ID. NOTE: some of these details are obtained from third party information.
- Affected:
- up to 2.0.25
- Fixed in:
- 2.0.25
- Disclosed:
- Jul 10, 2014
CVE-2014-4856 on NVD →
Crowdsignal Dashboard < 2.0.21 - Cross-Site Request Forgery
high
The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.0.21. This is due to missing or incorrect nonce validation in the rating_settings function. This makes it possible for unauthenticated attackers to have an unknown impact via a forged...
- CVSS:
- 7.1
- Affected:
- up to 2.0.21
- Fixed in:
- 2.0.21
- Disclosed:
- Nov 6, 2013
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.21
unknown
The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.0.21. This is due to missing or incorrect nonce validation in the rating_settings function. This makes it possible for unauthenticated attackers to have an unknown impact via a forged...
- Affected:
- up to 2.0.21
- Fixed in:
- 2.0.21
- Disclosed:
- Nov 6, 2013
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.32
unknown
Similar issue to the one in Jetpack's Polldaddy module.
- Affected:
- up to 2.0.32
- Fixed in:
- 2.0.32
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.24
unknown
The Crowdsignal Polls & Ratings WordPress plugin was affected by a polldaddy-org.php polldaddy-ratings-title-filter Parameter Reflected XSS security vulnerability.
- Affected:
- up to 2.0.24
- Fixed in:
- 2.0.24
Crowdsignal Dashboard – Polls, Surveys & more [polldaddy] < 2.0.21
unknown
The Crowdsignal Polls & Ratings WordPress plugin was affected by a Cross-Site Request Forgery security vulnerability.
- Affected:
- up to 2.0.21
- Fixed in:
- 2.0.21
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database