Impact
The Modern Polls plugin includes a Cross‑Site Request Forgery flaw that allows an attacker to embed malicious JavaScript into poll data that is then stored in the database. When the poll is displayed, the embedded script runs in the context of the site, enabling credential theft, defacement, or further infection. This stored XSS can affect every user who views the poll, compromising confidentiality, integrity, and availability of the site content.
Affected Systems
WordPress sites that use the felixtz Modern Polls plugin version 1.0.10 or earlier are vulnerable. The plugin can be found in the WordPress plugin repository, and any site that has installed it without updating beyond 1.0.10 is impacted.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a high‑severity vulnerability, yet the EPSS score (< 1%) suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by crafting a forged POST request that injects malicious payloads into poll configurations, typically from a separate domain while a logged‑in administrator or any privileged user visits the malicious site.
OpenCVE Enrichment
EUVD