WordPress security by component
CP Polls
Plugin description
CP Polls is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 7.1.
Plugin slug:
cp-pollsLatest vulnerability
CVE-2016-20067: CP Polls: Cross-site request forgery
CP Polls is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is 1.0.8.
| Safe version |
|
||
|---|---|---|---|
| Jun 15, 2026 |
CVE-2016-20067
CP Polls: Cross-site request forgery
CP Polls is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is 1.0.8.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2016-20066
CP Polls: Cross-site scripting
CP Polls is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 1.0.8.
|
See mitigation notes |
CVE5.1
NVDPending
|
| Jun 20, 2025 |
CVE-2025-50025
CP Polls: Cross-site scripting
CP Polls is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Oct 06, 2024 |
CVE-2024-47297
CP Polls: Cross-site scripting
CP Polls is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| May 17, 2024 |
CVE-2024-24874
CP Polls: Cross-site scripting
CP Polls is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.3
NVDPending
|
| May 17, 2024 |
CVE-2024-24873
CP Polls: A security weakness
CP Polls is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 27, 2019 |
CVE-2015-9346
Cp Polls: Cross-site scripting
Cp Polls is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 27, 2019 |
CVE-2014-10395
Cp Polls: Cross-site scripting
Cp Polls is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|