CVE-2024-3601 MEDIUM

CVE-2024-3601: Poll Maker – Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Email Enumeration

Vendor Ays-Pro
Product Poll Maker – Versus Polls, Anonymous Polls, Image Polls
Weakness CWE-862 · Missing authorization
Published May 2, 2024
Last update April 8, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_poll_create_author function in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to extract email addresses by enumerating them one character at a time.

Explanation of Vulnerability in Simple Terms

02Summary

The Poll Maker plugin for WordPress contains a missing authorization check that allows unauthenticated attackers to read sensitive poll data. An attacker can access poll information without logging in or having permission to view it. This affects versions up to 5.1.8. Update to a version newer than 5.1.8 to resolve the issue.

What an attacker can do

03Attacker Capabilities

Read poll data and responses without authentication or authorization.

Potential impact on your site

04Site Impact

Unauthenticated visitors can view private or restricted poll information intended only for authorized users.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

May 2, 2024 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE