SQL Injection Vulnerability in TS Poll Plugin for WordPress
CVE-2025-3470
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 April 2025
What is CVE-2025-3470?
The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is affected by a severe SQL Injection vulnerability. This issue arises from inadequate escaping of the user-supplied 's' parameter and the lack of robust preparation in existing SQL queries. Authenticated users with Administrator-level access can exploit this flaw to inject additional SQL commands into existing queries, potentially enabling them to retrieve sensitive data from the database. This vulnerability impacts all versions up to and including 2.4.6, posing significant risks to the confidentiality and integrity of the information stored.
Affected Version(s)
TS Poll – Survey, Versus Poll, Image Poll, Video Poll * <= 2.4.6