Origin Validation Flaw in YOP Poll Plugin for WordPress
CVE-2026-85682

8.8HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-85682?

The YOP Poll plugin for WordPress is susceptible to an origin validation error across all versions up to and including 7.0.10. This vulnerability arises from the plugin's use of postMessage() to transmit a wp_rest nonce to window.opener with a wildcard targetOrigin. Consequently, this flaw allows unauthenticated attackers to exploit the system, enabling them to steal a REST nonce associated with an Administrator's session. By luring an Administrator to an attacker-controlled page, an attacker can leverage this nonce to alter the Administrator’s email and password, ultimately leading to a complete account takeover.

Affected Version(s)

YOP Poll 0 <= 7.0.10

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Supakiad S. (m3ez)
.