Description
Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YOP Poll: from n/a through <= 6.5.38.
Published: 2025-11-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The YOP Poll plugin for WordPress contains a missing authorization flaw that permits users to perform actions beyond their intended permissions. This broken access control allows attackers to manipulate polls, harvest votes, or potentially alter poll content, thereby compromising the integrity of the poll data and potentially affecting the overall trust in the WordPress site. The weakness corresponds to CWE-862, which highlights failures to enforce proper authorization checks.

Affected Systems

WordPress sites using the YOP Poll plugin version 6.5.38 or earlier are impacted. The vulnerability applies to all supported installations of the plugin that have not applied the newer release where the access control issue is addressed.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at this time. Because it is not listed in CISA KEV, there have been no known active exploit campaigns targeting this flaw. The most likely attack vector involves a malicious or compromised user account that gains unintended capabilities through the plugin’s configuration interfaces. An attacker would need to exploit the missing authorization to elevate privileges within the poll management features. If successful, the attacker could change poll results or add fraudulent entries without detection.

Generated by OpenCVE AI on April 29, 2026 at 23:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest YOP Poll plugin update (latest release after 6.5.38) to fix the broken access control
  • If an update cannot be applied immediately, restrict the plugin’s functionalities to a limited role or disable public poll interaction for untrusted users
  • Ensure WordPress role‑based permissions are correctly configured so that only approved administrators can modify poll settings or edit results
  • Monitor poll activity for unusual vote patterns or unauthorized changes and review logs for suspicious access attempts

Generated by OpenCVE AI on April 29, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Yop-poll
Yop-poll yop-poll
Yop-poll yop Poll
Vendors & Products Wordpress
Wordpress wordpress
Yop-poll
Yop-poll yop-poll
Yop-poll yop Poll

Thu, 13 Nov 2025 09:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YOP Poll: from n/a through <= 6.5.38.
Title WordPress YOP Poll plugin <= 6.5.38 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
Yop-poll Yop-poll Yop Poll
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:14.526Z

Reserved: 2025-10-31T11:23:19.707Z

Link: CVE-2025-64370

cve-icon Vulnrichment

Updated: 2025-11-13T16:01:03.360Z

cve-icon NVD

Status : Deferred

Published: 2025-11-13T10:15:53.567

Modified: 2026-04-27T16:16:41.610

Link: CVE-2025-64370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:15:23Z

Weaknesses