CVE-2016-20066 MEDIUM

CVE-2016-20066: WordPress CP Polls 1.0.8 Persistent Cross-Site Scripting

Vendor Dwbooster
Product CP Polls
Weakness CWE-79 · XSS
Published June 15, 2026
Last update June 15, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

Description

WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitized file upload functionality. Attackers can upload files containing script payloads with event handlers like onerror attributes to execute arbitrary JavaScript in the browsers of users viewing the affected content.

Key dates

Disclosure timeline

June 15, 2026 CVE published
June 15, 2026 Record updated