Authentication Bypass in YOP Poll by yourownprogrammer
CVE-2023-46611

5.3MEDIUM

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
2 January 2025

Summary

The YOP Poll plugin developed by yourownprogrammer is susceptible to an authentication bypass vulnerability due to inadequate security measures. This flaw enables unauthorized users to manipulate voting results without proper authentication, affecting the integrity of the polling process. The vulnerability impacts all versions from n/a up to 6.5.28, highlighting the importance of keeping plugins updated and implementing robust access controls.

Affected Version(s)

YOP Poll <= 6.5.28

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

qilin_99 (Patchstack Alliance)
.