Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqjg-6w6p-5mh7

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.

EPSS

Процентиль: 13%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 месяца назад

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.

EPSS

Процентиль: 13%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290