Extension WordPress
Vulnérabilités YOP Poll
Cette page rassemble les failles publiées pour YOP Poll, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de YOP Poll
14 fiches
YOP Poll <= 6.5.38 – Missing Authorization
The YOP Poll plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.5.38. This makes it possible for unauthenticated attackers to perform an…
*-6.5.38
6.5.39
02/11/2025
YOP Poll <= 6.5.37 – Unauthenticated Stored Cross-Site Scripting
The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.37 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-6.5.37
6.5.38
12/10/2025
YOP Poll <= 6.5.26 – Race Condition to Vote Manipulation
The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated attackers to…
*-6.5.26
6.5.27
13/11/2023
YOP Poll <= 6.5.28 – Reusable Captcha via validateImage
The YOP Poll plugin for WordPress is vulnerable to captcha bypass due to a reusable captcha bypass in the validateImage function in all versions up to, and including, 6.5.28. This makes it possible for unauthenticated attackers to vote…
*-6.5.28
6.5.29
24/10/2023
YOP Poll <= 6.4.2 – IP Spoofing via X-Forwarded-For header
The YOP Poll plugin for WordPress is vulnerable to IP spoofing via the X-Forwarded-For header in versions up to, and including, 6.4.2. This allows attackers to bypass any restrictions based on IP address that have been configured in…
*-6.4.2
6.4.3
11/07/2022
YOP Poll <= 6.3.4 – Author+ Stored Cross-Site Scripting
The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue
*-6.3.4
6.3.5
14/02/2022
YOP Poll <= 6.3.0 – Author+ Stored Cross-Site Scripting via Options Module
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll – Options module where a user with a role as low as author is allowed to execute…
*-6.3.0
6.3.1
15/10/2021
YOP Poll <= 6.3.0 – Author+ Stored Cross-Site Scripting via Preview Module
The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary script…
*-6.3.0
6.3.1
15/10/2021
YOP Poll <= 6.2.7 – Unauthenticated Stored Cross-Site Scripting
In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as…
*-6.2.7
6.2.8
17/06/2021
YOP Poll <= 6.1.4 – Authenticated Stored Cross-Site Scripting
The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web…
[*, 6.1.5)
6.1.5
24/04/2020
YOP Poll <= 6.1.1 – Reflected Cross-Site Scripting
The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting
[*, 6.1.2)
6.1.2
15/01/2020
YOP Poll <= 6.0.2 – Reflected Cross-Site Scripting via poll_id Parameter
The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
[*, 6.0.3)
6.0.3
05/02/2019
YOP Poll <= 5.8.0 – Reflected Cross-Site Scripting
The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.8.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
[*, 5.8.1)
5.8.1
23/03/2017
YOP Poll <= 5.7.3 – Reflected Cross-Site Scripting
The YOP Poll plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘yop_poll_set_wordpress_vote’ parameter in versions up to, and including, 5.7.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-5.7.3
5.7.4
08/07/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.