The Wp Polls Project maintains a WordPress polling plugin that, despite a narrow product scope, occupies a prominent position within the WordPress ecosystem where it is widely deployed for survey and poll functionality. Vulnerability exposure in this plugin reflects the typical surface of WordPress extensions: input handling and integration challenges in a plugin architecture. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wp Polls Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9352CRITICAL The wp-polls plugin before 2.72 for WordPress has SQL injection. | Aug 27, 2019 | 9.8 | 29 | NO | NO |
CVE-2016-10936MEDIUM The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option. | Aug 27, 2019 | 6.1 | 21 | NO | NO |
CVE-2024-13426MEDIUM The WP-Polls plugin for WordPress is vulnerable to SQL Injection via COOKIE in all versions up to, and including, 2.77.2 due to insufficient escaping on the user supplied parameter | Jan 22, 2025 | 5.3 | 17 | NO | NO |
Auth. (subscriber+) Race Condition vulnerability in WP-Polls plugin <= 2.76.0 on WordPress. | Nov 18, 2022 | 3.1 | 16 | NO | NO |
CVE-2022-1581MEDIUM The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitati | Nov 21, 2022 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wp Polls Project.
Media articles that mention a CVE ID that affects a product developed by Wp Polls Project — matched by CVE ID, not by vendor name.