PT-2026-49204 · WordPress · Cp-Polls
CVE-2016-20066
·
Published
2026-06-15
·
Updated
2026-06-15
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress CP Polls versions prior to 1.0.9
Description
The software contains a persistent cross-site scripting issue allowing attackers to inject malicious scripts through unsanitized file upload functionality. Attackers can upload files containing script payloads with event handlers, such as
onerror attributes, to execute arbitrary JavaScript in the browsers of users viewing the content. Additionally, the software is susceptible to Cross-Site Request Forgery due to missing or incorrect nonce validation on a function. This allows unauthenticated attackers to update settings and inject malicious web scripts by tricking a site administrator into clicking a forged link.Recommendations
Update to a version newer than 1.0.8.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cp-Polls