Yop-poll
Yop-poll YOP Poll: vulnerabilidades y CVE
Yop-poll YOP Poll tiene 11 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85682 | Alta (8.8) | 0.14% | — | 24 sept 2026 | The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a… |
| CVE-2026-14840 | Media (5.3) | 0.35% | — | 1 ago 2026 | The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing… |
| CVE-2025-64370 | Media (5.3) | 0.22% | — | 13 nov 2025 | Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YOP Poll: from n/a through <= 6.5.38. |
| CVE-2025-62040 | Alta (7.1) | 0.28% | — | 6 nov 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YOP YOP Poll yop-poll.This issue affects YOP Poll: from n/a through <= 6.5.37. |
| CVE-2023-46611 | Media (5.3) | 0.41% | — | 2 ene 2025 | Authentication Bypass by Primary Weakness vulnerability in yourownprogrammer YOP Poll allows Authentication Bypass.This issue affects YOP Poll: from n/a through 6.5.28. |
| CVE-2023-6109 | Baja (3.7) | 0.37% | — | 14 nov 2023 | The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible for unauthenticated… |
| CVE-2022-1600 | Media (5.3) | 0.77% | — | 1 ago 2022 | The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations. |
| CVE-2021-24834 | Media (5.4) | 1.5% | — | 17 nov 2021 | The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as low as author is allowed to execute… |
| CVE-2021-24833 | Media (5.4) | 1.1% | — | 17 nov 2021 | The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as author is allowed to execute arbitrary… |
| CVE-2021-24454 | Media (6.1) | 1.6% | — | 12 jul 2021 | In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting… |
| CVE-2017-2127 | Media (5.4) | 0.94% | — | 28 abr 2017 | Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.