vendor:
YOP Polls
by:
inspired - Toby Jackson
8,8
CVSS
HIGH
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: YOP Polls
Affected Version From: 6.2.7
Affected Version To: 6.2.7
Patch Exists: YES
Related CWE: N/A
CPE: a:yop_poll:yop_poll
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2021
WordPress Plugin YOP Polls 6.2.7 – Stored Cross Site Scripting (XSS)
When a poll is created that allows other answers and then the setting is enabled for displaying the other responses after submission, the other answer is not sanitized when displayed back to the user, showing an XSS vulnerability. It is, however, correctly sanitized when displaying the other choices on the initial vote page.
Mitigation:
Update to the latest version of the plugin.