Beta

Report

Responsive Poll <= 1.3.2 is vulnerable to Unauthenticated Manipulation With Polls (delete, clone, or view a hidden poll) vulnerability

Unauthenticated
Published
2020-04-12

The TS Poll – Best Poll Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'wp_ajax_nopriv' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to to manipulate polls, e.g., delete, clone, or view a hidden poll.

CVSS

Score:9.8

Severity:Critical

Version: 1.3.2

There is a patch available in v1.3.4 and we strongly recommend you update to this version as soon as possible.