6.1

CVE-2021-24454

Exploit

YOP Poll < 6.2.8 - Stored Cross-Site Scripting

YOP Poll <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting

In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the XSS payload depends on the 'Show results' option selected, which could be before or after sending the vote for example.
Mögliche Gegenmaßnahme
YOP Poll: Update to version 6.2.8, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yop-pollYop Poll SwPlatformwordpress Version < 6.2.8
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt YOP Poll
Version *-6.2.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.6% 0.726
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://wpscan.com/vulnerability/48ade7a5-5abb-4267-b9b6-13e31e1b3e91
Third Party Advisory
Exploit
https://www.in-spired.xyz/discovering-wordpress-plugin-yop-polls-v6-2-7-stored-xss/
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/5df238dd-6269-4ee0-a0f4-12bdb74f74e8
Third Party Advisory