PT-2026-67052 · WordPress · Yop Poll

·

CVE-2026-14840

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions YOP Poll WordPress plugin versions prior to 7.0.6
Description The plugin fails to validate the origin IP address of a connection and relies on client-controlled forwarding headers to enforce per-IP vote restrictions. This allows unauthenticated attackers to bypass vote limits and cast unlimited votes on public polls.
Recommendations Update YOP Poll WordPress plugin to version 7.0.6 or later.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14840

Affected Products

Yop Poll