plugin

Social Polls By Opinionstage Vulnerabilities

14 known security issues reported for the Social Polls By Opinionstage WordPress plugin. Most recent disclosed Jan 19, 2026.

3 high 4 medium

Running Social Polls By Opinionstage on your site? Check whether your installed version is affected.

Scan your site free

Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 - Unauthenticated Stored Cross-Site Scripting

high

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 19.6.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...

CVSS:
7.2
Affected:
up to 19.6.25
Fixed in:
19.6.25
Disclosed:
Jan 19, 2026

Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 - Unauthenticated Stored Cross-Site Scripting

high

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 19.6.25 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...

CVSS:
7.2
Affected:
up to 19.6.25
Fixed in:
19.6.25
Disclosed:
Jan 19, 2026

CVE-2019-25297 on NVD →

Poll, Survey &amp; Quiz Maker Plugin by Opinion Stage [social-polls-by-opinionstage] < 19.6.25

unknown

[en] Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site scripting (XSS) vulnerability via multiple parameters due to insufficient input validation and output escaping. An unauthenticated attacker can inject arbitrary script into content that executes...

Affected:
up to 19.6.25
Fixed in:
19.6.25
Disclosed:
Jan 16, 2026

CVE-2019-25297 on NVD →

Poll, Survey &amp; Quiz Maker Plugin by Opinion Stage [social-polls-by-opinionstage] <= 19.12.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in Assaf Parag Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through <= 19.12.1.

Affected:
up to 19.12.1
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68594 on NVD →

Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Missing Authorization

medium

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 19.12.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 19.12.0
Fixed in:
19.12.1
Disclosed:
Dec 22, 2025

CVE-2025-68594 on NVD →

Poll, Survey &amp; Quiz Maker Plugin by Opinion Stage [social-polls-by-opinionstage] < 19.12.1

unknown

[en] The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.12.0. This is due to missing or insufficient nonce validation on the disconnect_account_action function. This makes it possible for unauthenticated attacke...

Affected:
up to 19.12.1
Fixed in:
19.12.1
Disclosed:
Nov 27, 2025

CVE-2025-13143 on NVD →

Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.12.0 - Cross-Site Request Forgery to Account Disconnection

medium

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.12.0. This is due to missing or insufficient nonce validation on the disconnect_account_action function. This makes it possible for unauthenticated attackers to...

CVSS:
4.3
Affected:
up to 19.12.0
Fixed in:
19.12.1
Disclosed:
Nov 26, 2025

CVE-2025-13143 on NVD →

Poll, Survey &amp; Quiz Maker Plugin by Opinion Stage [social-polls-by-opinionstage] <= 19.11.0 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Assaf Parag Poll, Survey & Quiz Maker Plugin by Opinion Stage allows PHP Local File Inclusion. This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through 19.11.0.

Affected:
up to 19.11.0
Fix:
No patched version reported
Disclosed:
Aug 28, 2025

CVE-2025-53328 on NVD →

Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.11.0 - Unauthenticated Local File Inclusion

high

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 19.11.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. Th...

CVSS:
8.1
Affected:
up to 19.11.0
Fixed in:
19.11.1
Disclosed:
Aug 26, 2025

CVE-2025-53328 on NVD →

Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.9.0 - Incorrect Authorization to Authenticated (Contributor+) Plugin Settings Update

medium

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on several functions in all versions up to, and including, 19.9.0. This makes it possible for authenticated attackers, with Contributor-level access and a...

CVSS:
4.3
Affected:
up to 19.9.0
Fixed in:
19.10.0
Disclosed:
Jun 16, 2025

CVE-2025-3880 on NVD →

Poll, Survey & Quiz Maker Plugin by Opinion Stage <= 19.6.24 - Unauthenticated Stored Cross-Site Scripting

medium

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 19.6.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...

CVSS:
6.1
Affected:
up to 19.6.24
Fixed in:
19.6.25
Disclosed:
Sep 16, 2019

Poll, Survey &amp; Quiz Maker Plugin by Opinion Stage [social-polls-by-opinionstage] < 19.6.25

unknown

The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 19.6.24 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...

Affected:
up to 19.6.25
Fixed in:
19.6.25
Disclosed:
Sep 16, 2019

Poll, Survey &amp; Quiz Maker Plugin by Opinion Stage [social-polls-by-opinionstage] < 19.6.25

unknown

This vulnerability has been seen actively exploited in the wild.

Affected:
up to 19.6.25
Fixed in:
19.6.25

Poll, Survey &amp; Quiz Maker Plugin by Opinion Stage [social-polls-by-opinionstage] < 19.10.0

unknown
Affected:
up to 19.10.0
Fixed in:
19.10.0

CVE-2025-3880 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database