Impact
This vulnerability is a missing authorization flaw that allows an attacker with minimal access to bypass security controls and manipulate poll settings, create, edit, or delete polls, or otherwise affect data integrity and confidentiality in a WordPress site that uses the TS Poll plugin. The weakness is a classic broken access control (CWE‑862).
Affected Systems
WordPress sites running the totalsoft TS Poll plugin, version 2.5.5 or earlier. The issue applies to all releases from the earliest available build up through 2.5.5 inclusive, with no specific build numbers listed beyond that range.
Risk and Exploitability
The CVSS score of 4.3 places this incident in the low severity category, and the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. This vulnerability is not yet listed in the CISA KEV catalog and no publicly known exploits exist. The attack vector is inferred to be via standard web request handling on the WordPress site, where an attacker can craft requests to the poll administration endpoints to trigger unprotected actions."
OpenCVE Enrichment