Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Pak0S

#27461of 56,326
9.8Total CVSS
Vulnerabilities · 1
PT-2020-12762
9.8
2020-04-13
Totalsoft · Responsive Poll · CVE-2020-11673
**Name of the Vulnerable Software and Affected Versions** Responsive Poll versions 1.3.4 and earlier **Description** An issue allows an unauthenticated user to manipulate polls, including deletion, cloning, or viewing hidden polls. This is due to the usage of the `wp ajax nopriv` function in `Includes/Total-Soft-Poll-Ajax.php` for sensitive operations. **Recommendations** For Responsive Poll versions 1.3.4 and earlier, consider disabling the sensitive operations within the `wp ajax nopriv` function in `Includes/Total-Soft-Poll-Ajax.php` until a patch is available. Restrict access to the `Includes/Total-Soft-Poll-Ajax.php` file to minimize the risk of exploitation.