Cross-Site Scripting Vulnerability in Democracy Poll Plugin for WordPress
CVE-2017-18520
6.1MEDIUM
What is CVE-2017-18520?
The Democracy Poll plugin for WordPress, prior to version 5.4, is susceptible to Cross-Site Scripting (XSS) attacks. The vulnerability arises in the update_l10n function located in admin/class.DemAdminInit.php, allowing attackers to inject malicious scripts through unsanitized input. This could lead to unauthorized script execution in the context of the affected user, posing a risk to site security and potentially compromising sensitive information.