What the vulnerability does
01Description
Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
What the vulnerability does
Authenticated (admin+) Cross-Site Scripting (XSS) vulnerability in wpdevart Poll, Survey, Questionnaire and Voting system plugin <= 1.7.4 at WordPress.
Explanation of Vulnerability in Simple Terms
The Poll, Survey, Questionnaire and Voting system WordPress plugin through version 1.7.4 contains a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious JavaScript into poll or survey content. When other users view the affected poll, the injected script executes in their browser, potentially stealing session data or performing actions on their behalf. The vulnerability requires user interaction—victims must visit the page containing the malicious poll.
What an attacker can do
Inject JavaScript that runs in visitors' browsers when they view a poll or survey.
Potential impact on your site
An admin account compromise could inject malicious scripts into polls, affecting all site visitors who view them.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site and the victim must view the affected poll.
Key dates
External resources
Related vulnerabilities