Reflected XSS Vulnerability in WP Easy Poll by aviplugins.com
CVE-2025-32562

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 April 2025

What is CVE-2025-32562?

The WP Easy Poll plugin by aviplugins.com contains an issue related to improper neutralization of input during web page generation, leading to a reflected Cross-site Scripting (XSS) vulnerability. This security flaw can allow an attacker to inject malicious scripts into web pages viewed by other users, potentially enabling session hijacking, redirection to malicious sites, or stealing sensitive information. Users of WP Easy Poll, especially those operating versions up to 2.2.9, are encouraged to review the plugin’s security measures and implement necessary updates to mitigate exposure to this threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WP Easy Poll <= 2.2.9

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.