SQL Injection Vulnerability in TS Poll Plugin for WordPress
CVE-2025-3470
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 April 2025
What is CVE-2025-3470?
The TS Poll β Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is affected by a severe SQL Injection vulnerability. This issue arises from inadequate escaping of the user-supplied 's' parameter and the lack of robust preparation in existing SQL queries. Authenticated users with Administrator-level access can exploit this flaw to inject additional SQL commands into existing queries, potentially enabling them to retrieve sensitive data from the database. This vulnerability impacts all versions up to and including 2.4.6, posing significant risks to the confidentiality and integrity of the information stored.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
TS Poll β Survey, Versus Poll, Image Poll, Video Poll * <= 2.4.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved