What the vulnerability does
01Description
Missing Authorization vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a through <= 4.12.0.
Explanation of Vulnerability in Simple Terms
02Summary
Total Poll Lite versions 4.12.0 and earlier lack proper authorization checks, allowing authenticated users to access sensitive poll data and functionality they should not have permission to view or modify. An attacker with a low-privilege account can read confidential poll information without additional interaction. Update to a version newer than 4.12.0 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive poll data and functionality restricted to higher-privilege users.
Potential impact on your site
04Site Impact
Confidential poll data may be exposed to users who should not have access to it.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site.
Key dates
06Disclosure timeline
April 8, 2026
CVE published
April 29, 2026
Record updated