SQL Injection Vulnerability in TS Poll Plugin for WordPress
CVE-2025-3470

4.9MEDIUM

What is CVE-2025-3470?

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is affected by a severe SQL Injection vulnerability. This issue arises from inadequate escaping of the user-supplied 's' parameter and the lack of robust preparation in existing SQL queries. Authenticated users with Administrator-level access can exploit this flaw to inject additional SQL commands into existing queries, potentially enabling them to retrieve sensitive data from the database. This vulnerability impacts all versions up to and including 2.4.6, posing significant risks to the confidentiality and integrity of the information stored.

Affected Version(s)

TS Poll – Survey, Versus Poll, Image Poll, Video Poll * <= 2.4.6

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Octovian Aurora Parikesit
.