Race Condition Vulnerability in YOP Poll Plugin for WordPress
CVE-2023-6109

3.7LOW

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
14 November 2023

Summary

The YOP Poll plugin for WordPress is susceptible to a race condition, allowing unauthenticated attackers to exploit improper restrictions in the add() function. This vulnerability enables attackers to cast multiple votes in a single poll, even when it is configured to limit voting to one vote per individual. This could lead to skewed results and undermine the integrity of polling data. Website administrators should update to secure versions and apply necessary security practices to mitigate the risk of exploitation.

Affected Version(s)

YOP Poll * <= 6.5.26

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RIN MIYACHI
.