The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 5.8.9 via the 'ays_finish_poll' AJAX action. This makes it possible for unauthenticated attackers to retrieve admin email information which is exposed in the poll response.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-54982 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 5.8.9 via the 'ays_finish_poll' AJAX action. This makes it possible for unauthenticated attackers to retrieve admin email information which is exposed in the poll response.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 24 Aug 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Ays-pro
Ays-pro poll Maker
Wordpress
Wordpress wordpress
Vendors & Products Ays-pro
Ays-pro poll Maker
Wordpress
Wordpress wordpress

Mon, 18 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 16 Aug 2025 03:00:00 +0000

Type Values Removed Values Added
Description The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 5.8.9 via the 'ays_finish_poll' AJAX action. This makes it possible for unauthenticated attackers to retrieve admin email information which is exposed in the poll response.
Title Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.8.9 - Unauthenticated Basic Information Exposure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-08-18T13:59:35.350Z

Reserved: 2024-12-12T15:46:31.908Z

Link: CVE-2024-12575

cve-icon Vulnrichment

Updated: 2025-08-18T13:59:32.339Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-16T03:15:25.427

Modified: 2025-08-18T20:16:28.750

Link: CVE-2024-12575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-24T22:19:14Z