WP-Polls <= 2.77.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP-Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.77.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 4.4
- Affected:
- up to 2.77.3
- Fixed in:
- 3.0.0
- Disclosed:
- Jul 22, 2026
CVE-2025-68081 on NVD →
WP-Polls <= 2.77.2 - Unauthenticated SQL Injection to Stored Cross-Site Scripting
medium
The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQ...
- CVSS:
- 5.4
- Affected:
- up to 2.77.2
- Fixed in:
- 2.77.3
- Disclosed:
- Jan 21, 2025
CVE-2024-13426 on NVD →
WP-Polls <= 2.75.6 - IP Validation Bypass
medium
The WP-Polls plugin for WordPress is vulnerable to IP Validation Bypass in versions up to, and including, 2.75.6. This is due to the plugin prioritizing easier to spoof IP detection mechanisms. This makes it possible for unauthenticated attackers to bypass IP-based limitations to polling.
- CVSS:
- 6.5
- Affected:
- up to 2.75.6
- Fixed in:
- 2.76.0
- Disclosed:
- Oct 31, 2022
CVE-2022-1581 on NVD →
WP-Polls <= 2.76.0 - Race Condition
medium
The WP-Polls plugin for WordPress is vulnerable to Race Condition in the function vote_poll_process() in versions up to, and including, 3.3.4. This can lead to unpredictable polling result changes when certain conditions are met.
- CVSS:
- 4.3
- Affected:
- up to 2.76.0
- Fixed in:
- 2.77.0
- Disclosed:
- Oct 5, 2022
CVE-2022-40130 on NVD →
WP-Polls <= 2.71 - SQL Injection
critical
The wp-polls plugin before 2.72 for WordPress has SQL injection.
- CVSS:
- 9.8
- Affected:
- up to 2.71
- Fixed in:
- 2.72
- Disclosed:
- Aug 26, 2019
CVE-2015-9352 on NVD →
WP-Polls <= 2.73 - Cross-Site Scripting
medium
The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.
- CVSS:
- 6.1
- Affected:
- up to 2.73
- Fixed in:
- 2.73.1
- Disclosed:
- Jul 29, 2016
CVE-2016-10936 on NVD →
WP-Polls <= 2.70 - Stored Cross-Site Scripting
high
The WP-Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pollq_question and polla_answers’ parameters in versions up to, and including, 2.70 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 7.2
- Affected:
- up to 2.70
- Fixed in:
- 2.71
- Disclosed:
- Aug 14, 2015
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database