← WordPress Vulnerabilities
WordPress security by component

YOP Poll

YOP Poll creates, publishes, and manages polls with voting options and results display in WordPress.

YOP Poll (yop-poll) is a WordPress plugin with 12 published CVE records in this archive. The latest tracked vulnerability was published Aug 01, 2026; the highest published CVSS base score is 7.1.

Plugin slug: yop-poll

CVE-2026-14840: YOP Poll trusts spoofable forwarding headers for vote limits

YOP Poll before 7.0.6 uses client-controlled forwarding headers as the voter's origin address when enforcing its per-IP restriction. An unauthenticated visitor can change the supplied address between requests and cast unlimited votes on a public poll.

PublishedAug 01, 2026
Known safe version7.0.6
Published vulnerabilities for yop-poll
Safe version
Aug 01, 2026 CVE-2026-14840
YOP Poll trusts spoofable forwarding headers for vote limits
YOP Poll before 7.0.6 uses client-controlled forwarding headers as the voter's origin address when enforcing its per-IP restriction. An unauthenticated visitor can change the supplied address between requests and cast unlimited votes on a public poll.
7.0.6
CVE5.3
NVDPending
Nov 13, 2025 CVE-2025-64370
YOP Poll: A security weakness
YOP Poll is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 06, 2025 CVE-2025-62040
YOP Poll: Cross-site scripting
YOP Poll is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jan 02, 2025 CVE-2023-46611
YOP Poll: Privilege escalation or authentication bypass
YOP Poll is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE5.3
NVDPending
Nov 14, 2023 CVE-2023-6109
YOP Poll: A security weakness
YOP Poll is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD3.7
Aug 01, 2022 CVE-2022-1600
YOP Poll: A security weakness
YOP Poll is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD5.3
Mar 07, 2022 CVE-2022-0205
YOP Poll: Cross-site scripting
YOP Poll is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Nov 17, 2021 CVE-2021-24834
YOP Poll: Cross-site scripting
YOP Poll is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Nov 17, 2021 CVE-2021-24833
YOP Poll: Cross-site scripting
YOP Poll is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD5.4
Oct 25, 2021 CVE-2021-24885
YOP Poll: Cross-site scripting
YOP Poll is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jul 12, 2021 CVE-2021-24454
YOP Poll: Cross-site scripting
YOP Poll is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Mar 22, 2019 CVE-2019-9914
Yop Poll: Cross-site scripting
Yop Poll is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1