# YOP Poll <= 7.0.12 - Unauthenticated Information Exposure of Results on Registered-Only Polls

- **ID:** WPSEC-2026-0462
- **Plugin:** YOP Poll (`yop-poll`), https://wordpress.org/plugins/yop-poll/
- **Affected versions:** from 7.0.0 before 7.0.13
- **Fixed in:** 7.0.13 (Update to 7.0.13 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/yop-poll
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0462/

## Description

The YOP Poll plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 up to, and including, 7.0.12. This is because the plugin does not enforce the poll's 'Show results to: Registered' setting when it builds the public poll data returned by the poll results and vote REST endpoints and embedded in rendered polls. This makes it possible for unauthenticated attackers to view per-answer vote counts and totals of polls that the site owner has restricted to logged-in users, either after casting a guest vote or without voting when the poll's results are otherwise displayable. No voter personal data is exposed.

## References

- https://wpsec.com/vuln/WPSEC-2026-0462/
- https://plugins.svn.wordpress.org/yop-poll/tags/7.0.13/
- https://wordpress.org/plugins/yop-poll/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0462/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
