Description
Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
Published: 2026-07-23
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the WordPress WP‑Polls plugin allows unvalidated or improperly encoded data to be reflected in the administrative interface, resulting in Cross Site Scripting. An attacker who can inject a malicious payload into poll data can cause a browser executing the admin session to run arbitrary JavaScript. This can lead to credential theft, session hijacking, or further exploitation within the WordPress installation, as the payload executes with the privileges of the logged‑in administrator.

Affected Systems

WordPress sites running the WP‑Polls plugin (developed by Lester Chan) version 2.77.3 or earlier. These plugins are normally obtained from the WordPress plugin repository and are actively used on public websites that publish polls to their visitors.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.9, indicating moderate severity. The EPSS score of less than 1% suggests that, as of the last measurement, the likelihood of exploitation in the wild is low. The issue is not listed in the CISA KEV catalog. The most probable attack path involves an attacker crafting or inserting a poll entry with malicious script content that is later viewed by an administrator in the backend. Because the script executes with admin privileges, the impact is limited to sites where the admin interface is accessible and the plugin is in a vulnerable state.

Generated by OpenCVE AI on August 3, 2026 at 22:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a later, patched version of the WP‑Polls plugin.
  • If an upgrade is not immediately possible, remove the WP‑Polls plugin from the admin interfaces to prevent execution of vulnerable code.
  • Review all existing polls for malicious scripts and clean or delete any that contain unescaped input.

Generated by OpenCVE AI on August 3, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Lester Chan
Lester Chan wp-polls
Wordpress
Wordpress wordpress
Vendors & Products Lester Chan
Lester Chan wp-polls
Wordpress
Wordpress wordpress
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.
Title WordPress WP-Polls plugin <= 2.77.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Lester Chan Wp-polls
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:54:19.963Z

Reserved: 2025-12-15T10:01:29.282Z

Link: CVE-2025-68081

cve-icon Vulnrichment

Updated: 2026-07-23T13:54:43.325Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:17:05.170

Modified: 2026-07-23T16:17:12.717

Link: CVE-2025-68081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')