YOP Poll 7.0.0-7.0.5 - IP Spoofing to Vote Restriction Bypass
medium
The YOP Poll plugin for WordPress is vulnerable to IP Spoofing in versions 7.0.0 to 7.0.5. This makes it possible for unauthenticated attackers to bypass vote restrictions.
- CVSS:
- 5.3
- Affected:
- 7.0.0 – 7.0.5
- Fixed in:
- 7.0.6
- Disclosed:
- Aug 6, 2026
CVE-2026-14840 on NVD →
YOP Poll [yop-poll] <= 6.5.38 (unfixed)
unknown
[en] Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YOP Poll: from n/a through <= 6.5.38.
- Affected:
- up to 6.5.38
- Fix:
- No patched version reported
- Disclosed:
- Nov 13, 2025
CVE-2025-64370 on NVD →
YOP Poll [yop-poll] < 6.5.38
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YOP YOP Poll yop-poll.This issue affects YOP Poll: from n/a through <= 6.5.37.
- Affected:
- up to 6.5.38
- Fixed in:
- 6.5.38
- Disclosed:
- Nov 6, 2025
CVE-2025-62040 on NVD →
YOP Poll <= 6.5.38 - Missing Authorization
medium
The YOP Poll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.5.38. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 6.5.38
- Fixed in:
- 6.5.39
- Disclosed:
- Nov 2, 2025
CVE-2025-64370 on NVD →
YOP Poll <= 6.5.37 - Unauthenticated Stored Cross-Site Scripting
high
The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.37 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 6.5.37
- Fixed in:
- 6.5.38
- Disclosed:
- Oct 12, 2025
CVE-2025-62040 on NVD →
YOP Poll [yop-poll] < 6.5.29
unknown
[en] Authentication Bypass by Primary Weakness vulnerability in yourownprogrammer YOP Poll allows Authentication Bypass.This issue affects YOP Poll: from n/a through 6.5.28.
- Affected:
- up to 6.5.29
- Fixed in:
- 6.5.29
- Disclosed:
- Jan 2, 2025
CVE-2023-46611 on NVD →
YOP Poll [yop-poll] < 6.5.27
unknown
[en] The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated attackers to place multiple votes on a single poll even when the poll is set to one vote per perso...
- Affected:
- up to 6.5.27
- Fixed in:
- 6.5.27
- Disclosed:
- Nov 14, 2023
CVE-2023-6109 on NVD →
YOP Poll <= 6.5.26 - Race Condition to Vote Manipulation
medium
The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated attackers to place multiple votes on a single poll even when the poll is set to one vote per person.
- CVSS:
- 5.3
- Affected:
- up to 6.5.26
- Fixed in:
- 6.5.27
- Disclosed:
- Nov 13, 2023
CVE-2023-6109 on NVD →
YOP Poll <= 6.5.28 - Reusable Captcha via validateImage
medium
The YOP Poll plugin for WordPress is vulnerable to captcha bypass due to a reusable captcha bypass in the validateImage function in all versions up to, and including, 6.5.28. This makes it possible for unauthenticated attackers to vote multiple times using the same captcha image
- CVSS:
- 5.3
- Affected:
- up to 6.5.28
- Fixed in:
- 6.5.29
- Disclosed:
- Oct 24, 2023
CVE-2023-46611 on NVD →
YOP Poll [yop-poll] < 6.4.3
unknown
[en] The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
- Affected:
- up to 6.4.3
- Fixed in:
- 6.4.3
- Disclosed:
- Aug 1, 2022
CVE-2022-1600 on NVD →
YOP Poll <= 6.4.2 - IP Spoofing via X-Forwarded-For header
medium
The YOP Poll plugin for WordPress is vulnerable to IP spoofing via the X-Forwarded-For header in versions up to, and including, 6.4.2. This allows attackers to bypass any restrictions based on IP address that have been configured in the plugin.
- CVSS:
- 5.3
- Affected:
- up to 6.4.2
- Fixed in:
- 6.4.3
- Disclosed:
- Jul 11, 2022
CVE-2022-1600 on NVD →
YOP Poll [yop-poll] < 6.3.5
unknown
[en] The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue
- Affected:
- up to 6.3.5
- Fixed in:
- 6.3.5
- Disclosed:
- Mar 7, 2022
CVE-2022-0205 on NVD →
YOP Poll <= 6.3.4 - Author+ Stored Cross-Site Scripting
medium
The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue
- CVSS:
- 6.4
- Affected:
- up to 6.3.4
- Fixed in:
- 6.3.5
- Disclosed:
- Feb 14, 2022
CVE-2022-0205 on NVD →
YOP Poll [yop-poll] < 6.3.5
unknown
[en] The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficie...
- Affected:
- up to 6.3.5
- Fixed in:
- 6.3.5
- Disclosed:
- Nov 17, 2021
CVE-2021-24834 on NVD →
YOP Poll [yop-poll] < 6.3.5
unknown
[en] The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient vali...
- Affected:
- up to 6.3.5
- Fixed in:
- 6.3.5
- Disclosed:
- Nov 17, 2021
CVE-2021-24833 on NVD →
YOP Poll [yop-poll] < 6.1.2
unknown
[en] The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
- Affected:
- up to 6.1.2
- Fixed in:
- 6.1.2
- Disclosed:
- Oct 25, 2021
CVE-2021-24885 on NVD →
YOP Poll <= 6.3.0 - Author+ Stored Cross-Site Scripting via Preview Module
medium
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validatio...
- CVSS:
- 5.4
- Affected:
- up to 6.3.0
- Fixed in:
- 6.3.1
- Disclosed:
- Oct 15, 2021
CVE-2021-24833 on NVD →
YOP Poll <= 6.3.0 - Author+ Stored Cross-Site Scripting via Options Module
medium
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient va...
- CVSS:
- 5.4
- Affected:
- up to 6.3.0
- Fixed in:
- 6.3.1
- Disclosed:
- Oct 15, 2021
CVE-2021-24834 on NVD →
YOP Poll [yop-poll] < 6.2.8
unknown
[en] In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the...
- Affected:
- up to 6.2.8
- Fixed in:
- 6.2.8
- Disclosed:
- Jul 12, 2021
CVE-2021-24454 on NVD →
YOP Poll <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting
medium
In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the XSS...
- CVSS:
- 6.1
- Affected:
- up to 6.2.7
- Fixed in:
- 6.2.8
- Disclosed:
- Jun 17, 2021
CVE-2021-24454 on NVD →
YOP Poll <= 6.1.4 - Authenticated Stored Cross-Site Scripting
medium
The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- CVSS:
- 6.4
- Affected:
- up to 6.1.5
- Fixed in:
- 6.1.5
- Disclosed:
- Apr 24, 2020
YOP Poll [yop-poll] < 6.1.5
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Jeroen Mulder in WordPress YOP Poll plugin (versions <= 6.1.4).
- Affected:
- up to 6.1.5
- Fixed in:
- 6.1.5
- Disclosed:
- Apr 24, 2020
YOP Poll [yop-poll] < 6.1.5
unknown
The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- Affected:
- up to 6.1.5
- Fixed in:
- 6.1.5
- Disclosed:
- Apr 24, 2020
YOP Poll <= 6.1.1 - Reflected Cross-Site Scripting
medium
The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
- CVSS:
- 6.1
- Affected:
- up to 6.1.2
- Fixed in:
- 6.1.2
- Disclosed:
- Jan 15, 2020
CVE-2021-24885 on NVD →
YOP Poll [yop-poll] < 6.0.3
unknown
[en] The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
- Affected:
- up to 6.0.3
- Fixed in:
- 6.0.3
- Disclosed:
- Mar 21, 2019
CVE-2019-9914 on NVD →
YOP Poll [yop-poll] < 6.0.3
unknown
Reflected Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress YOP Poll plugin (versions <= 6.0.2).
- Affected:
- up to 6.0.3
- Fixed in:
- 6.0.3
- Disclosed:
- Mar 12, 2019
YOP Poll <= 6.0.2 - Reflected Cross-Site Scripting via poll_id Parameter
medium
The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
- CVSS:
- 6.1
- Affected:
- up to 6.0.3
- Fixed in:
- 6.0.3
- Disclosed:
- Feb 5, 2019
CVE-2019-9914 on NVD →
YOP Poll [yop-poll] < 5.8.1
unknown
[en] Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 5.8.1
- Fixed in:
- 5.8.1
- Disclosed:
- Apr 28, 2017
CVE-2017-2127 on NVD →
YOP Poll <= 5.8.0 - Reflected Cross-Site Scripting
medium
The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 5.8.1
- Fixed in:
- 5.8.1
- Disclosed:
- Mar 23, 2017
CVE-2017-2127 on NVD →
YOP Poll <= 5.7.3 - Reflected Cross-Site Scripting
medium
The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘yop_poll_set_wordpress_vote’ parameter in versions up to, and including, 5.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 6.1
- Affected:
- up to 5.7.3
- Fixed in:
- 5.7.4
- Disclosed:
- Jul 8, 2015
YOP Poll [yop-poll] < 5.7.4
unknown
The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘yop_poll_set_wordpress_vote’ parameter in versions up to, and including, 5.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- Affected:
- up to 5.7.4
- Fixed in:
- 5.7.4
- Disclosed:
- Jul 8, 2015
YOP Poll [yop-poll] < 5.7.4
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 5.7.4
- Fixed in:
- 5.7.4
- Disclosed:
- Jul 8, 2015
YOP Poll [yop-poll] < 5.7.4
unknown
The YOP Poll plugin exposes a number of AJAX requests to the public (see lines 15-40 in th efile yop-poll/inc/admin.php). An XSS vulnerability has been found in at least one of these functions – namely yop_poll_set_wordpress_vote. This function is available to both registered and non-registered users. The fields...
- Affected:
- up to 5.7.4
- Fixed in:
- 5.7.4
YOP Poll [yop-poll] < 6.1.5
unknown
If you add a new poll, and place a malicious script in the question/answer fields and then press Preview, the script will run. The preview option is available for the editor & administrator role, which makes these roles vulnerable to XSS attacks.
- Affected:
- up to 6.1.5
- Fixed in:
- 6.1.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database