QID 150600
Date Published: 2022-11-28
QID 150600: WordPress WP-Polls Plugin: Race Condition Vulnerability (CVE-2022-40130)
WP-Polls is a WordPress plugin which adds an AJAX poll system to WordPress blog and is extremely customizable via templates and css styles.
A Race Condition vulnerability exists in WP-Polls plugins which requires subscriber or higher role user authentication for exploitation.
Affected versions:
WP-Polls prior to version 2.77.0
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could allow an attacker to manipulate voting.
Solution
Customers are advised to upgrade to WP-Polls 2.77.0 or later to remediate this vulnerability. For more information regarding this vulnerability please refer Patchstack Advisory
Vendor References
CVEs related to QID 150600
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WP-Polls Downloads |
|