Reflected XSS in YOP Poll Plugin for WordPress
CVE-2019-9914
6.1MEDIUM
What is CVE-2019-9914?
The YOP Poll plugin for WordPress, prior to version 6.0.3, is susceptible to a reflected cross-site scripting (XSS) vulnerability. This flaw occurs at the endpoint wp-admin/admin.php?page=yop-polls&action=view-votes where an attacker can manipulate the poll_id parameter. When a user accesses a specially crafted URL, it could potentially allow attackers to execute arbitrary JavaScript code in the context of the user's session, compromising the security and integrity of affected systems.