PT-2020-7346 · WordPress · Wordpress Poll Plugin+1
Published
2020-02-13
·
Updated
2020-02-19
·
CVE-2013-1400
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
WordPress Poll Plugin version 34.5
Description:
The issue allows attackers to execute arbitrary SQL commands via the
pollid or poll id parameter in a "viewPollResults" or "userlogs" action. This is made possible by multiple SQL injection vulnerabilities in the CWPPoll.js file.Recommendations:
For WordPress Poll Plugin version 34.5, consider disabling the CWPPoll.js file or restricting access to the "viewPollResults" and "userlogs" actions until a patch is available. Avoid using the
pollid or poll id parameters in these actions to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cwppoll.Js
Wordpress Poll Plugin