Reflected XSS Vulnerability in Pinpoll Plugin by WordPress
CVE-2025-68889
7.1HIGH
What is CVE-2025-68889?
The Pinpoll plugin for WordPress has a vulnerability that allows attackers to exploit improper sanitization of user input, leading to Reflected Cross-site Scripting (XSS). Through this flaw, malicious scripts can be executed in the user's browser, presenting potential data theft and session hijacking risks when users interact with affected versions of the plugin. It's critical for users to update to secure versions to mitigate this risk.
Affected Version(s)
Pinpoll <= n/a
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Xuan Chien | Patchstack Bug Bounty Program