What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4.
Explanation of Vulnerability in Simple Terms
WP Poll Maker versions 3.4 and earlier allow authenticated users with low privileges to upload files without restriction. An attacker can upload malicious files to execute code on the site, compromise data, or take the site offline. The vulnerability requires a logged-in account but no special permissions.
What an attacker can do
Upload and execute malicious files on the site, including PHP code.
Potential impact on your site
Site could be fully compromised, including data theft, defacement, or complete takeover.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities