Impact
The vulnerability is a Cross‑Site Request Forgery that allows an attacker to store malicious JavaScript in a poll through the Simple Poll WordPress plugin. When a user later views the poll, the script executes in that user’s browser, potentially compromising confidentiality and integrity by stealing session cookies, injecting phishing content, or defacing the site. The vulnerability is rated moderate (CVSS score 7.1) and maps to CWE‑352.
Affected Systems
The flaw resides in the tosend.it Simple Poll WordPress plugin, affecting all releases up to and including version 1.1.1. Users operating any unpatched installation of this plugin are susceptible.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low likelihood of widespread exploitation, and the flaw is not listed in the CISA KEV catalog. The likely exploitation path is through a CSRF attack, where a victim is tricked into visiting a crafted URL that submits a poll submission containing malicious JavaScript. The impact is scoped to the victim user’s browsing session; however, repeated or targeted attacks could enable broader data compromise.
OpenCVE Enrichment
EUVD