YOP Poll <= 7.0.12 - Unauthenticated Information Exposure of Results on Registered-Only Polls
- ID
- WPSEC-2026-0462
- Plugin
- YOP Poll (yop-poll)
- Affected
- from 7.0.0 before 7.0.13
- Remediation
- Update to 7.0.13 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
- Attack surface
- YOP Poll on WPSec AttackSurface
- Fix released
- Published
Description
The YOP Poll plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 up to, and including, 7.0.12. This is because the plugin does not enforce the poll's 'Show results to: Registered' setting when it builds the public poll data returned by the poll results and vote REST endpoints and embedded in rendered polls. This makes it possible for unauthenticated attackers to view per-answer vote counts and totals of polls that the site owner has restricted to logged-in users, either after casting a guest vote or without voting when the poll's results are otherwise displayable. No voter personal data is exposed.
References
- https://wpsec.com/vuln/WPSEC-2026-0462/
- https://plugins.svn.wordpress.org/yop-poll/tags/7.0.13/
- https://wordpress.org/plugins/yop-poll/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS