What the vulnerability does
01Description
Missing Authorization vulnerability in Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage social-polls-by-opinionstage allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll, Survey & Quiz Maker Plugin by Opinion Stage: from n/a through <= 19.12.0.
Explanation of Vulnerability in Simple Terms
02Summary
The Poll, Survey & Quiz Maker plugin by Opinion Stage through version 19.12.0 lacks proper authorization checks on certain functions. An unauthenticated attacker can trigger actions that degrade site availability without needing to log in or interact with a user. The vulnerability does not expose sensitive data or allow content modification.
What an attacker can do
03Attacker Capabilities
Make requests that degrade the site's availability or performance.
Potential impact on your site
04Site Impact
Site performance or availability may be degraded by unauthenticated requests to the plugin.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 24, 2025
CVE published
April 28, 2026
Record updated