What the vulnerability does
01Description
Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress.
Explanation of Vulnerability in Simple Terms
WP-Polls version 2.76.0 and earlier contains an integrity vulnerability affecting authenticated users with low privileges. An attacker with a low-privilege account can modify poll data or settings without proper authorization checks. The vulnerability requires network access and an active login but does not require user interaction. Confidentiality and availability are not impacted.
What an attacker can do
Modify poll data or settings on the site with a low-privilege account.
Potential impact on your site
Low-privilege users can alter poll content or configuration, potentially spreading misinformation or disrupting polls.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account and network access.
Key dates
External resources