PT-2024-39653 · WordPress · The Poll Maker – Versus Polls

Ivan Kuzymchak

·

Published

2024-10-26

·

Updated

2024-10-28

·

CVE-2024-9475

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress versions up to, and including, 5.4.6
Description The issue is related to generic SQL Injection via the order by parameter due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This allows authenticated attackers with administrator-level permissions and above to append additional SQL queries into already existing queries, which can be used to extract sensitive information from the database.
Recommendations For versions up to, and including, 5.4.6, update to a version that fixes the SQL Injection issue. As a temporary workaround, consider restricting access to the order by parameter to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-9475

Affected Products

The Poll Maker – Versus Polls