Yop Poll is a WordPress polling and survey plugin with a modest vulnerability footprint concentrated in its core product. The plugin's disclosures center on application-level input-handling and access-control concerns typical of WordPress extensions deployed across a distributed ecosystem. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yop Poll over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24885MEDIUM The YOP Poll WordPress plugin before 6.1.2 does not escape the perpage parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | Oct 25, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-24454MEDIUM In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can | Jul 12, 2021 | 6.1 | 21 | NO | NO |
CVE-2022-1600MEDIUM The YOP Poll WordPress plugin before 6.4.3 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitatio | Aug 1, 2022 | 5.3 | 20 | NO | NO |
CVE-2021-24834MEDIUM The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in the Create Poll - Options module where a user with a role as l | Nov 17, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-24833MEDIUM The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in the Admin preview module where a user with a role as low as a | Nov 17, 2021 | 5.4 | 20 | NO | NO |
CVE-2019-9914MEDIUM The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS. | Mar 22, 2019 | 6.1 | 17 | NO | NO |
CVE-2017-2127MEDIUM Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Apr 28, 2017 | 5.4 | 16 | NO | NO |
The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This m | Nov 14, 2023 | 3.7 | 15 | NO | NO |
CVE-2022-0205MEDIUM The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a | Mar 7, 2022 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yop Poll.
Media articles that mention a CVE ID that affects a product developed by Yop Poll — matched by CVE ID, not by vendor name.