WordPress · Yop Poll · CVE-2026-14840
**Name of the Vulnerable Software and Affected Versions**
YOP Poll WordPress plugin versions prior to 7.0.6
**Description**
The plugin fails to validate the origin IP address of a connection and relies on client-controlled forwarding headers to enforce per-IP vote restrictions. This allows unauthenticated attackers to bypass vote limits and cast unlimited votes on public polls.
**Recommendations**
Update YOP Poll WordPress plugin to version 7.0.6 or later.