Beta

Report

Polls Widget <= 1.5.2 is vulnerable to Unauthenticated Blind SQL Injection (SQLi) vulnerability

Unauthenticated
Published
2021-06-21

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

CVSS

Score:6.5

Severity:Medium

Version: 1.5.2

There is a patch available in v1.5.3 and we strongly recommend you update to this version as soon as possible.