📦 Poll Maker

by Ays Pro

🔍 What is Poll Maker?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-3600

HIGH CVSS 7.2 Apr 19, 2024

This vulnerability in the Poll Maker WordPress plugin allows unauthenticated attackers to create malicious quizzes with stored cross-site scripting (XSS) payloads. When users visit these compromised q...

CVE-2021-24651

HIGH CVSS 7.5 Oct 11, 2021

The Poll Maker WordPress plugin before version 3.4.2 contains an unauthenticated SQL injection vulnerability via the ays_finish_poll AJAX action. Attackers can use timing attacks to exfiltrate sensiti...

CVE-2021-24483

HIGH CVSS 7.2 Aug 2, 2021

This SQL injection vulnerability in the Poll Maker WordPress plugin allows authenticated attackers with admin dashboard access to execute arbitrary SQL commands. It affects WordPress sites running vul...

CVE-2024-13602

MEDIUM CVSS 4.8 Mar 16, 2025

The Poll Maker WordPress plugin before version 5.5.4 contains a stored cross-site scripting (XSS) vulnerability in its settings. This allows authenticated administrators to inject malicious scripts th...

CVE-2023-45766

MEDIUM CVSS 5.3 Jan 2, 2025

This CVE describes a missing authorization vulnerability in the Poll Maker WordPress plugin that allows attackers to exploit incorrectly configured access control security levels. It affects all versi...

CVE-2023-50904

MEDIUM CVSS 5.3 Dec 9, 2024

This CVE describes a missing authorization vulnerability in the Poll Maker WordPress plugin that allows attackers to exploit incorrectly configured access control security levels. Attackers can perfor...

CVE-2024-12115

MEDIUM CVSS 4.3 Dec 7, 2024

This CSRF vulnerability in the Poll Maker WordPress plugin allows unauthenticated attackers to duplicate polls by tricking administrators into clicking malicious links. All WordPress sites using Poll ...

CVE-2024-9475

MEDIUM CVSS 4.9 Oct 26, 2024

This SQL injection vulnerability in the Poll Maker WordPress plugin allows authenticated attackers with administrator permissions to execute arbitrary SQL queries. Attackers can extract sensitive data...

CVE-2024-3601

MEDIUM CVSS 5.3 May 2, 2024

The Poll Maker WordPress plugin has an authorization vulnerability that allows unauthenticated attackers to extract email addresses through character-by-character enumeration. This affects all WordPre...