Impact
The vulnerability is a missing authorization flaw that permits exploitation of incorrectly configured access control security levels within the Opinion Stage Poll, Survey & Quiz Maker Plugin for WordPress. An attacker can gain unauthorized access to modify or read polling data, quiz content, or configuration settings that should be restricted to privileged users. This type of weakness could enable the creation of distracting or misleading content, or expose sensitive information collected through polls and surveys.
Affected Systems
WordPress installations running Opinion Stage Poll, Survey & Quiz Maker Plugin by Opinion Stage, versions from the earliest available release up to and including 19.12.0. Any site that has not applied the later fix is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector involves users with any authenticated role that has access to the plugin interface; attackers could manipulate permissions or directly target exposed endpoints if the plugin’s access controls are misconfigured. Depending on the site’s role hierarchy, a regular contributor might be able to perform actions reserved for administrators.
OpenCVE Enrichment