PT-2024-37670 · WordPress · Light Poll Wordpress Plugin

Published

2024-08-01

·

Updated

2025-06-09

·

CVE-2024-6496

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Light Poll WordPress plugin versions through 1.0.0
Description The issue concerns a lack of CSRF checks when deleting polls, which could allow attackers to make logged-in users perform such actions via a CSRF attack.
Recommendations For versions through 1.0.0, as a temporary workaround, consider disabling the poll deletion feature until a patch is available. Restrict access to the poll management interface to minimize the risk of exploitation. Avoid using the plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-6496

Affected Products

Light Poll Wordpress Plugin