cleantalk
Vulnerabilities and Security Researches

YOP Poll, CVE-2022-0205

CVE, Research URL

CVE-2022-0205

Application

YOP Poll

Published on
Mar 07, 2022
Research Description
The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue
Affected versions
max 6.3.5.
Status
vulnerable