Loading HuntDB...

GHSA-w4r6-cjx2-64gc

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to create quizzes and inject malicious web scripts into them that execute when a user visits the page.

Related CVEs

Key Information

GHSA ID
GHSA-w4r6-cjx2-64gc
Published
April 19, 2024 3:31 AM
Last Modified
May 28, 2025 9:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.