Impact
A flaw in the WordPress WP‑Polls plugin allows unvalidated or improperly encoded data to be reflected in the administrative interface, resulting in Cross Site Scripting. An attacker who can inject a malicious payload into poll data can cause a browser executing the admin session to run arbitrary JavaScript. This can lead to credential theft, session hijacking, or further exploitation within the WordPress installation, as the payload executes with the privileges of the logged‑in administrator.
Affected Systems
WordPress sites running the WP‑Polls plugin (developed by Lester Chan) version 2.77.3 or earlier. These plugins are normally obtained from the WordPress plugin repository and are actively used on public websites that publish polls to their visitors.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.9, indicating moderate severity. The EPSS score of less than 1% suggests that, as of the last measurement, the likelihood of exploitation in the wild is low. The issue is not listed in the CISA KEV catalog. The most probable attack path involves an attacker crafting or inserting a poll entry with malicious script content that is later viewed by an administrator in the backend. Because the script executes with admin privileges, the impact is limited to sites where the admin interface is accessible and the plugin is in a vulnerable state.
OpenCVE Enrichment