plugin

Yop Poll Vulnerabilities

34 known security issues reported for the Yop Poll WordPress plugin. Most recent disclosed Aug 6, 2026.

1 high 14 medium

Running Yop Poll on your site? Check whether your installed version is affected.

Scan your site free

YOP Poll 7.0.0-7.0.5 - IP Spoofing to Vote Restriction Bypass

medium

The YOP Poll plugin for WordPress is vulnerable to IP Spoofing in versions 7.0.0 to 7.0.5. This makes it possible for unauthenticated attackers to bypass vote restrictions.

CVSS:
5.3
Affected:
7.0.0 – 7.0.5
Fixed in:
7.0.6
Disclosed:
Aug 6, 2026

CVE-2026-14840 on NVD →

YOP Poll [yop-poll] <= 6.5.38 (unfixed)

unknown

[en] Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YOP Poll: from n/a through <= 6.5.38.

Affected:
up to 6.5.38
Fix:
No patched version reported
Disclosed:
Nov 13, 2025

CVE-2025-64370 on NVD →

YOP Poll [yop-poll] < 6.5.38

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YOP YOP Poll yop-poll.This issue affects YOP Poll: from n/a through <= 6.5.37.

Affected:
up to 6.5.38
Fixed in:
6.5.38
Disclosed:
Nov 6, 2025

CVE-2025-62040 on NVD →

YOP Poll <= 6.5.38 - Missing Authorization

medium

The YOP Poll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.5.38. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 6.5.38
Fixed in:
6.5.39
Disclosed:
Nov 2, 2025

CVE-2025-64370 on NVD →

YOP Poll <= 6.5.37 - Unauthenticated Stored Cross-Site Scripting

high

The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.37 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 6.5.37
Fixed in:
6.5.38
Disclosed:
Oct 12, 2025

CVE-2025-62040 on NVD →

YOP Poll [yop-poll] < 6.5.29

unknown

[en] Authentication Bypass by Primary Weakness vulnerability in yourownprogrammer YOP Poll allows Authentication Bypass.This issue affects YOP Poll: from n/a through 6.5.28.

Affected:
up to 6.5.29
Fixed in:
6.5.29
Disclosed:
Jan 2, 2025

CVE-2023-46611 on NVD →

YOP Poll [yop-poll] < 6.5.27

unknown

[en] The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated attackers to place multiple votes on a single poll even when the poll is set to one vote per perso...

Affected:
up to 6.5.27
Fixed in:
6.5.27
Disclosed:
Nov 14, 2023

CVE-2023-6109 on NVD →

YOP Poll <= 6.5.26 - Race Condition to Vote Manipulation

medium

The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated attackers to place multiple votes on a single poll even when the poll is set to one vote per person.

CVSS:
5.3
Affected:
up to 6.5.26
Fixed in:
6.5.27
Disclosed:
Nov 13, 2023

CVE-2023-6109 on NVD →

YOP Poll <= 6.5.28 - Reusable Captcha via validateImage

medium

The YOP Poll plugin for WordPress is vulnerable to captcha bypass due to a reusable captcha bypass in the validateImage function in all versions up to, and including, 6.5.28. This makes it possible for unauthenticated attackers to vote multiple times using the same captcha image

CVSS:
5.3
Affected:
up to 6.5.28
Fixed in:
6.5.29
Disclosed:
Oct 24, 2023

CVE-2023-46611 on NVD →

YOP Poll [yop-poll] < 6.4.3

unknown

[en] The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.

Affected:
up to 6.4.3
Fixed in:
6.4.3
Disclosed:
Aug 1, 2022

CVE-2022-1600 on NVD →

YOP Poll <= 6.4.2 - IP Spoofing via X-Forwarded-For header

medium

The YOP Poll plugin for WordPress is vulnerable to IP spoofing via the X-Forwarded-For header in versions up to, and including, 6.4.2. This allows attackers to bypass any restrictions based on IP address that have been configured in the plugin.

CVSS:
5.3
Affected:
up to 6.4.2
Fixed in:
6.4.3
Disclosed:
Jul 11, 2022

CVE-2022-1600 on NVD →

YOP Poll [yop-poll] < 6.3.5

unknown

[en] The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue

Affected:
up to 6.3.5
Fixed in:
6.3.5
Disclosed:
Mar 7, 2022

CVE-2022-0205 on NVD →

YOP Poll <= 6.3.4 - Author+ Stored Cross-Site Scripting

medium

The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue

CVSS:
6.4
Affected:
up to 6.3.4
Fixed in:
6.3.5
Disclosed:
Feb 14, 2022

CVE-2022-0205 on NVD →

YOP Poll [yop-poll] < 6.3.5

unknown

[en] The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficie...

Affected:
up to 6.3.5
Fixed in:
6.3.5
Disclosed:
Nov 17, 2021

CVE-2021-24834 on NVD →

YOP Poll [yop-poll] < 6.3.5

unknown

[en] The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient vali...

Affected:
up to 6.3.5
Fixed in:
6.3.5
Disclosed:
Nov 17, 2021

CVE-2021-24833 on NVD →

YOP Poll [yop-poll] < 6.1.2

unknown

[en] The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

Affected:
up to 6.1.2
Fixed in:
6.1.2
Disclosed:
Oct 25, 2021

CVE-2021-24885 on NVD →

YOP Poll <= 6.3.0 - Author+ Stored Cross-Site Scripting via Preview Module

medium

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validatio...

CVSS:
5.4
Affected:
up to 6.3.0
Fixed in:
6.3.1
Disclosed:
Oct 15, 2021

CVE-2021-24833 on NVD →

YOP Poll <= 6.3.0 - Author+ Stored Cross-Site Scripting via Options Module

medium

The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient va...

CVSS:
5.4
Affected:
up to 6.3.0
Fixed in:
6.3.1
Disclosed:
Oct 15, 2021

CVE-2021-24834 on NVD →

YOP Poll [yop-poll] < 6.2.8

unknown

[en] In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the...

Affected:
up to 6.2.8
Fixed in:
6.2.8
Disclosed:
Jul 12, 2021

CVE-2021-24454 on NVD →

YOP Poll <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting

medium

In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the XSS...

CVSS:
6.1
Affected:
up to 6.2.7
Fixed in:
6.2.8
Disclosed:
Jun 17, 2021

CVE-2021-24454 on NVD →

YOP Poll <= 6.1.4 - Authenticated Stored Cross-Site Scripting

medium

The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

CVSS:
6.4
Affected:
up to 6.1.5
Fixed in:
6.1.5
Disclosed:
Apr 24, 2020

YOP Poll [yop-poll] < 6.1.5

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by Jeroen Mulder in WordPress YOP Poll plugin (versions <= 6.1.4).

Affected:
up to 6.1.5
Fixed in:
6.1.5
Disclosed:
Apr 24, 2020

YOP Poll [yop-poll] < 6.1.5

unknown

The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

Affected:
up to 6.1.5
Fixed in:
6.1.5
Disclosed:
Apr 24, 2020

YOP Poll <= 6.1.1 - Reflected Cross-Site Scripting

medium

The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting

CVSS:
6.1
Affected:
up to 6.1.2
Fixed in:
6.1.2
Disclosed:
Jan 15, 2020

CVE-2021-24885 on NVD →

YOP Poll [yop-poll] < 6.0.3

unknown

[en] The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.

Affected:
up to 6.0.3
Fixed in:
6.0.3
Disclosed:
Mar 21, 2019

CVE-2019-9914 on NVD →

YOP Poll [yop-poll] < 6.0.3

unknown

Reflected Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress YOP Poll plugin (versions <= 6.0.2).

Affected:
up to 6.0.3
Fixed in:
6.0.3
Disclosed:
Mar 12, 2019

YOP Poll <= 6.0.2 - Reflected Cross-Site Scripting via poll_id Parameter

medium

The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.

CVSS:
6.1
Affected:
up to 6.0.3
Fixed in:
6.0.3
Disclosed:
Feb 5, 2019

CVE-2019-9914 on NVD →

YOP Poll [yop-poll] < 5.8.1

unknown

[en] Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 5.8.1
Fixed in:
5.8.1
Disclosed:
Apr 28, 2017

CVE-2017-2127 on NVD →

YOP Poll <= 5.8.0 - Reflected Cross-Site Scripting

medium

The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 5.8.1
Fixed in:
5.8.1
Disclosed:
Mar 23, 2017

CVE-2017-2127 on NVD →

YOP Poll <= 5.7.3 - Reflected Cross-Site Scripting

medium

The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘yop_poll_set_wordpress_vote’ parameter in versions up to, and including, 5.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
6.1
Affected:
up to 5.7.3
Fixed in:
5.7.4
Disclosed:
Jul 8, 2015

YOP Poll [yop-poll] < 5.7.4

unknown

The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘yop_poll_set_wordpress_vote’ parameter in versions up to, and including, 5.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

Affected:
up to 5.7.4
Fixed in:
5.7.4
Disclosed:
Jul 8, 2015

YOP Poll [yop-poll] < 5.7.4

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 5.7.4
Fixed in:
5.7.4
Disclosed:
Jul 8, 2015

YOP Poll [yop-poll] < 5.7.4

unknown

The YOP Poll plugin exposes a number of AJAX requests to the public (see lines 15-40 in th efile yop-poll/inc/admin.php). An XSS vulnerability has been found in at least one of these functions &ndash; namely yop_poll_set_wordpress_vote. This function is available to both registered and non-registered users. The fields...

Affected:
up to 5.7.4
Fixed in:
5.7.4

YOP Poll [yop-poll] < 6.1.5

unknown

If you add a new poll, and place a malicious script in the question/answer fields and then press Preview, the script will run. The preview option is available for the editor &amp; administrator role, which makes these roles vulnerable to XSS attacks.

Affected:
up to 6.1.5
Fixed in:
6.1.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database