Sensitive Information Exposure in Poll Maker Plugin for WordPress
CVE-2026-8995
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 May 2026
What is CVE-2026-8995?
The Poll Maker plugin for WordPress contains a vulnerability that allows authenticated attackers with subscriber-level access and above to exploit insufficient access controls. Specifically, the 'ays_poll_get_user_information' AJAX action is improperly secured, enabling these users to access the entire WP_User object, including sensitive information like the bcrypt password hash, user email, and roles. This sensitive data is typically protected and not exposed through standard WordPress interfaces. The absence of nonce verification and insufficient capability checks raise serious security concerns, potentially allowing for offline password-cracking attacks.
Affected Version(s)
Poll Maker by AYS β Versus Polls, Anonymous Polls, Image Polls 0 <= 6.3.7