Poll Maker
Vendor:
First CVE: Aug 2, 2021 · Active for 4 years
21
Total CVEs
More Total CVEs than 94% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Poll Maker over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2021
4 years ago
Most Recent CVE
Sep 22, 2025
306 days ago
CVE Severity & Scoring
Poll Maker21 CVEs
62%
29%
10%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (95.2%)
High1 (4.8%)
Unknown0 (0.0%)
User Interaction
None13 (61.9%)
Unknown0 (0.0%)
Required8 (38.1%)
Privileges Required
Low1 (4.8%)
High6 (28.6%)
None14 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-26971CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Poll Maker poll-maker allows Blind SQL Injection.This issue affects Po | Feb 25, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-24577CRITICAL Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a | Apr 17, 2025 | 9.8 | 25 | NO | NO |
CVE-2021-24651HIGH The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the res | Oct 11, 2021 | 7.5 | 25 | NO | NO |
CVE-2024-9475HIGH The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all versions up to, and includ | Oct 26, 2024 | 7.2 | 23 | NO | NO |
CVE-2021-24483HIGH The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did not use whitelist or validate the orderby parameter before us | Aug 2, 2021 | 7.2 | 23 | NO | NO |
CVE-2025-57954MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Poll Maker poll-maker allows DOM-Based XSS.This issue affects Poll Mak | Sep 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2023-34013HIGH Server-Side Request Forgery (SSRF) vulnerability in Poll Maker Team Poll Maker – Best WordPress Poll Plugin.This issue affects Poll Maker – Best WordPress Poll Plugin: from n/a thr | Nov 13, 2023 | 7.5 | 22 | NO | NO |
CVE-2025-47545HIGH Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Ays Pro Poll Maker poll-maker allows Leveraging Race Conditions.This is | May 7, 2025 | 8.1 | 21 | NO | NO |
CVE-2024-9874HIGH The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and in | Nov 9, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-3600MEDIUM The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJ | Apr 19, 2024 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Poll Maker
Top CWEs
Versions
No cataloged versions.