PT-2021-16165 · WordPress · Poll Maker

Apple502J

·

Published

2021-10-11

·

Updated

2022-11-09

·

CVE-2021-24651

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Poll Maker WordPress plugin versions prior to 3.4.2
Description The issue allows unauthenticated users to perform SQL injection via the ays finish poll AJAX action. Although the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate sensitive data, such as password hashes.
Recommendations For versions prior to 3.4.2, update to version 3.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the ays finish poll AJAX action to prevent potential exploitation.

Exploit

Fix

SQL injection

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2021-24651

Affected Products

Poll Maker