Extension WordPress
Vulnérabilités Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls, page 2
Cette page rassemble les failles publiées pour Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls
24 fiches
Poll Maker <= 4.0.1 – Admin+ Stored Cross-Site Scripting
The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed
*-4.0.1
4.0.2
04/05/2022
Poll Maker < 3.4.2 – Unauthenticated SQL Injection
The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate…
[*, 3.4.2)
3.4.2
13/09/2021
Poll Maker <= 3.2.8 – Reflected Cross-Site Scripting
The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-maker-settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.8.
*-3.2.8
3.2.9
26/07/2021
Poll Maker <= 3.2.0 – SQL Injection
The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL…
[*, 3.2.1)
3.2.1
29/06/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.