← WordPress Vulnerabilities
WordPress security by component

Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls

Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls is a WordPress component with 23 published CVE records in this archive. The latest tracked vulnerability was published May 29, 2026; the highest CVE/CNA score is 7.6.

Plugin slug: poll-maker

CVE-2026-8995: Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls: Sensitive information exposure

Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 6.3.7.

PublishedMay 29, 2026
Known safe version> 6.3.7
Safe version
May 29, 2026 CVE-2026-8995
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls: Sensitive information exposure
Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls is affected by sensitive information exposure. Exploitation requires at least subscriber-level access. Successful exploitation can disclose data that should not be available to the caller. The published affected range is <= 6.3.7.
> 6.3.7
CVE4.3
NVDPending
Nov 13, 2025 CVE-2025-12620
Poll Maker – Versus Polls, Anonymous Polls, Image Polls: SQL injection
Poll Maker – Versus Polls, Anonymous Polls, Image Polls is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVDPending
Sep 22, 2025 CVE-2025-57954
Poll Maker: Cross-site scripting
Poll Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
May 07, 2025 CVE-2025-47545
Poll Maker: A security weakness
Poll Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD8.1
Apr 17, 2025 CVE-2025-24577
Poll Maker: A security weakness
Poll Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD9.8
Mar 16, 2025 CVE-2024-13602
Poll Maker: Cross-site scripting
Poll Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Feb 25, 2025 CVE-2025-26971
Poll Maker: SQL injection
Poll Maker is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD9.8
Jan 21, 2025 CVE-2024-56277
Poll Maker: A security weakness
Poll Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 15, 2025 CVE-2024-56295
Poll Maker: A security weakness
Poll Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Jan 02, 2025 CVE-2023-45766
Poll Maker: A security weakness
Poll Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Dec 09, 2024 CVE-2023-50904
Poll Maker: A security weakness
Poll Maker is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Dec 07, 2024 CVE-2024-12115
Poll Maker – Versus Polls, Anonymous Polls, Image Polls: Cross-site request forgery
Poll Maker – Versus Polls, Anonymous Polls, Image Polls is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Nov 09, 2024 CVE-2024-9874
Poll Maker – Versus Polls, Anonymous Polls, Image Polls: SQL injection
Poll Maker – Versus Polls, Anonymous Polls, Image Polls is affected by SQL injection. Exploitation requires at least administrator-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVD7.2
Oct 26, 2024 CVE-2024-9475
Poll Maker – Versus Polls, Anonymous Polls, Image Polls: SQL injection
Poll Maker – Versus Polls, Anonymous Polls, Image Polls is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE4.9
NVD7.2
Oct 26, 2024 CVE-2024-9462
Poll Maker – Versus Polls, Anonymous Polls, Image Polls: Cross-site scripting
Poll Maker – Versus Polls, Anonymous Polls, Image Polls is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.5
NVD4.8
May 02, 2024 CVE-2024-3601
Poll Maker – Best WordPress Poll Plugin: A security weakness
Poll Maker – Best WordPress Poll Plugin is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 19, 2024 CVE-2024-3600
Poll Maker – Best WordPress Poll Plugin: Cross-site scripting
Poll Maker – Best WordPress Poll Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Nov 13, 2023 CVE-2023-34013
Poll Maker – Best WordPress Poll Plugin: Server-side request forgery
Poll Maker – Best WordPress Poll Plugin is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.4
NVD7.5
Sep 25, 2023 CVE-2023-41871
Poll Maker: Cross-site scripting
Poll Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 30, 2022 CVE-2022-1456
Poll Maker: Cross-site scripting
Poll Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Oct 11, 2021 CVE-2021-24651
Poll Maker: SQL injection
Poll Maker is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5
Aug 02, 2021 CVE-2021-34635
Poll Maker: Cross-site scripting
Poll Maker is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Aug 02, 2021 CVE-2021-24483
get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker: SQL injection
get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2