Impact
Simply Poll 1.4.1 for WordPress contains an injection flaw that permits attackers to inject arbitrary SQL through the pollid POST field. A malicious user can target the admin-ajax.php endpoint with the spAjaxResults action and a crafted pollid value, causing the server to run unintended SELECT statements and return the results in the response. This enables an unauthenticated actor to read sensitive database information such as usernames, passwords, or content, compromising confidentiality of the WordPress installation.
Affected Systems
The vulnerability affects the Simply Poll plugin distributed by Ollie Armstrong, specifically version 1.4.1. Any WordPress site deploying this plugin is at risk if the plugin is present and the exposed endpoint remains reachable.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score is not available, so exploitation probability is uncertain, but the unauthenticated nature of the attack and the public existence of attack examples imply a non‑negligible risk. The flaw is not listed in CISA KEV, but the potential for data exfiltration warrants immediate attention. Attackers could reach the vulnerable endpoint from any network that can reach the site, and no special privileges are required.
OpenCVE Enrichment