PT-2026-49204 · WordPress · Cp-Polls

CVE-2016-20066

·

Published

2026-06-15

·

Updated

2026-06-15

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress CP Polls versions prior to 1.0.9
Description The software contains a persistent cross-site scripting issue allowing attackers to inject malicious scripts through unsanitized file upload functionality. Attackers can upload files containing script payloads with event handlers, such as onerror attributes, to execute arbitrary JavaScript in the browsers of users viewing the content. Additionally, the software is susceptible to Cross-Site Request Forgery due to missing or incorrect nonce validation on a function. This allows unauthenticated attackers to update settings and inject malicious web scripts by tricking a site administrator into clicking a forged link.
Recommendations Update to a version newer than 1.0.8.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-20066

Affected Products

Cp-Polls