What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in InfoTheme WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in InfoTheme WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.1.
Explanation of Vulnerability in Simple Terms
WP Poll Maker versions up to 3.1 contain a path traversal vulnerability that allows authenticated users to cause the site to become unavailable. An attacker with low-level access can manipulate file paths to trigger a denial-of-service condition. The vulnerability requires valid login credentials but no additional user interaction.
What an attacker can do
Make the site unavailable by triggering a denial-of-service condition through path traversal.
Potential impact on your site
Site downtime or performance degradation if an authenticated user exploits this vulnerability.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities