cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-polls wp-polls

Direction: ascending
Jun 07, 2024

WP-Polls # CVE-2015-9352

CVE, Research URL

CVE-2015-9352

Application

WP-Polls

Date
Aug 27, 2019
Research Description
The wp-polls plugin before 2.72 for WordPress has SQL injection.
Affected versions
max 2.72.
Status
vulnerable

WP-Polls # CVE-2016-10936

CVE, Research URL

CVE-2016-10936

Application

WP-Polls

Date
Aug 27, 2019
Research Description
The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.
Affected versions
max 2.73.1.
Status
vulnerable

WP-Polls # CVE-2022-1581

CVE, Research URL

CVE-2022-1581

Application

WP-Polls

Date
Nov 21, 2022
Research Description
The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
Affected versions
max 2.76.0.
Status
vulnerable

WP-Polls # CVE-2022-40130

CVE, Research URL

CVE-2022-40130

Application

WP-Polls

Date
Nov 19, 2022
Research Description
Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress.
Affected versions
max 2.77.0.
Status
vulnerable
Jan 23, 2025

WP-Polls # CVE-2024-13426

CVE, Research URL

CVE-2024-13426

Application

WP-Polls

Date
Jan 22, 2025
Research Description
The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries. Those queries are stored and results are not displayed to the attacker, which means they cannot be exploited to obtain any additional information about the database. However, a properly configured payload allows for the injection of malicious JavaScript resulting in Stored Cross-Site Scripting.
Affected versions
max 2.77.3.
Status
vulnerable
Jun 16, 2026

WP-Polls # 8df1f4c9c90846d10a7bfef0359506601ccd7e10

Application

WP-Polls

Date
Aug 14, 2015
Research Description
WP-Polls [wp-polls] < 2.71 WP-Polls <= 2.70 - Stored Cross-Site Scripting The WP-Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pollq_question and polla_answers’ parameters in versions up to, and including, 2.70 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.71.
Status
vulnerable

WP-Polls # 505de41c7b96550c46d272f6f0bb954f02a6d10b

Application

WP-Polls

Date
Aug 14, 2015
Research Description
WP-Polls [wp-polls] < 2.71 WordPress Polls Plugin <= 2.70 - Cross Site Scripting (XSS) This plugin is prone to a cross site scripting vulnerability, because "pollq_question" and "polla_answers[]" parameters are not sanitized. Update the plugin.
Affected versions
max 2.71.
Status
vulnerable

WP-Polls # ac56379d-01fc-413b-bddd-cdb02ccae810

Application

WP-Polls

Date
-
Research Description
WP-Polls [wp-polls] < 2.73.1 (closed) WP-Polls &lt;= 2.73 - Authenticated Reflected Cross-Site Scripting (XSS) The WP-Polls WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 2.73.1.
Status
vulnerable

WP-Polls # 8497ceda-f72f-4c55-a4eb-616ba5c403ce

Application

WP-Polls

Date
-
Research Description
WP-Polls [wp-polls] < 2.70 (closed) WP-Polls &lt;= 2.70 - Stored Cross-Site Scripting (XSS) The /wp-admin/admin.php?page=wp-polls%2Fpolls-add.php page is vulnerable to XSS within the pollq_question and polla_answers[] parameters.
Affected versions
max 2.70.
Status
vulnerable
Jul 31, 2026

WP-Polls # CVE-2025-68081

CVE, Research URL

CVE-2025-68081

Application

WP-Polls

Date
Jul 23, 2026
Research Description
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
Affected versions
max 2.77.3.
Status
vulnerable