Anonymous Polls Plugin Vulnerable to SQL Injection
CVE-2024-9874

7.2HIGH

What is CVE-2024-9874?

The Poll Maker plugin for WordPress, including all versions up to and including 5.4.6, is susceptible to a time-based SQL Injection vulnerability due to inadequate parameter escaping. This flaw arises from an improperly prepared SQL query that allows authenticated users with Administrator-level access or higher to inject additional SQL statements. Attackers can exploit this vulnerability to retrieve sensitive information from the database, potentially leading to data breaches.

Affected Version(s)

Poll Maker – Versus Polls, Anonymous Polls, Image Polls * <= 5.4.6

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tmrswrr
.
CVE-2024-9874 : Anonymous Polls Plugin Vulnerable to SQL Injection