CVE-2022-40130 MEDIUM

CVE-2022-40130: WordPress WP-Polls plugin <= 2.76.0 - Auth. Race Condition vulnerability

Vendor Lester 'Gamerz' Chan
Product WP-Polls (WordPress plugin)
Published November 18, 2022
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress.

Explanation of Vulnerability in Simple Terms

02Summary

WP-Polls version 2.76.0 and earlier contains an integrity vulnerability affecting authenticated users with low privileges. An attacker with a low-privilege account can modify poll data or settings without proper authorization checks. The vulnerability requires network access and an active login but does not require user interaction. Confidentiality and availability are not impacted.

What an attacker can do

03Attacker Capabilities

Modify poll data or settings on the site with a low-privilege account.

Potential impact on your site

04Site Impact

Low-privilege users can alter poll content or configuration, potentially spreading misinformation or disrupting polls.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress user account and network access.

Key dates

06Disclosure timeline

November 18, 2022 CVE published
April 28, 2026 Record updated