Poll Maker Vulnerable to Stored Cross-Site Scripting
CVE-2024-3600
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 19 April 2024
What is CVE-2024-3600?
The Poll Maker โ Best WordPress Poll Plugin plugin for WordPress exhibits a vulnerability to Stored Cross-Site Scripting (XSS) due to an absence of proper capability checks on the ays_poll_maker_quick_start AJAX action. Additionally, all versions up to and including 5.1.8 lack sufficient escaping and sanitization measures. This deficiency enables unauthenticated attackers to craft quizzes that can embed malicious scripts, which execute without user consent when a targeted individual visits the page, significantly increasing the risk of data theft and site compromise.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Poll Maker โ Best WordPress Poll Plugin * <= 5.1.8
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved