Responsive Poll < 1.7.6 - Cross-Site Request Forgery to Cross-Site Scripting
highThe Responsive Poll plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions before 1.7.6 due to insufficient input sanitization and output escaping and missing nonce validation. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's b...
- CVSS:
- 8.8
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Jan 10, 2017