Beta

Report

Crowdsignal Dashboard – Polls, Surveys & more <= 2.0.24 is vulnerable to XSS

Unauthenticated
Published
2014-07-09

Cross-site scripting (XSS) vulnerability in the Polldaddy Polls & Ratings plugin before 2.0.25 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a ratings shortcode and a unique ID.

CVSS

Score:6.1

Severity:Medium

Version: 2.0.24

There is a patch available in v2.0.25 and we strongly recommend you update to this version as soon as possible.