Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-14840

Опубликовано: 01 авг. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.

EPSS

Процентиль: 13%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 5.3
github
около 2 месяцев назад

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.

EPSS

Процентиль: 13%
0.00222
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-290