Origin Validation Flaw in YOP Poll Plugin for WordPress
CVE-2026-85682
8.8HIGH
What is CVE-2026-85682?
The YOP Poll plugin for WordPress is susceptible to an origin validation error across all versions up to and including 7.0.10. This vulnerability arises from the plugin's use of postMessage() to transmit a wp_rest nonce to window.opener with a wildcard targetOrigin. Consequently, this flaw allows unauthenticated attackers to exploit the system, enabling them to steal a REST nonce associated with an Administrator's session. By luring an Administrator to an attacker-controlled page, an attacker can leverage this nonce to alter the Administrator’s email and password, ultimately leading to a complete account takeover.
Affected Version(s)
YOP Poll 0 <= 7.0.10