PT-2024-37670 · WordPress · Light Poll Wordpress Plugin

CVE-2024-6496

·

Published

2024-08-01

·

Updated

2025-06-09

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Light Poll WordPress plugin versions through 1.0.0
Description The issue concerns a lack of CSRF checks when deleting polls, which could allow attackers to make logged-in users perform such actions via a CSRF attack.
Recommendations For versions through 1.0.0, as a temporary workaround, consider disabling the poll deletion feature until a patch is available. Restrict access to the poll management interface to minimize the risk of exploitation. Avoid using the plugin until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-6496

Affected Products

Light Poll Wordpress Plugin