CVE-2021-24651 is a high-severity SQL injection vulnerability affecting the Poll Maker WordPress plugin prior to version 3.4.2. Unauthenticated attackers can exploit this flaw via the ays_finish_poll AJAX action. Although direct result disclosure is absent, a timing attack can be used to exfiltrate sensitive data like password hashes. Currently, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.2CPE matchmatch criteria | cpe:2.3:a:ays-pro:poll_maker:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.