Vulnerabilities / YOP Poll / WPSEC-2026-0462

YOP Poll <= 7.0.12 - Unauthenticated Information Exposure of Results on Registered-Only Polls

Medium 5.3 CWE-200Fixed in 7.0.13
ID
WPSEC-2026-0462
Plugin
YOP Poll (yop-poll)
Affected
from 7.0.0 before 7.0.13
Remediation
Update to 7.0.13 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
YOP Poll on WPSec AttackSurface
Fix released
Published

Description

The YOP Poll plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 up to, and including, 7.0.12. This is because the plugin does not enforce the poll's 'Show results to: Registered' setting when it builds the public poll data returned by the poll results and vote REST endpoints and embedded in rendered polls. This makes it possible for unauthenticated attackers to view per-answer vote counts and totals of polls that the site owner has restricted to logged-in users, either after casting a guest vote or without voting when the poll's results are otherwise displayable. No voter personal data is exposed.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0