PT-2026-97734 · WordPress · Yop Poll

·

CVE-2026-85682

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YOP Poll versions prior to 7.0.11
Description The plugin contains an origin validation error where it transmits a wp rest nonce to window.opener using the postMessage() function with a wildcard targetOrigin. This allows unauthenticated attackers to steal a REST nonce associated with a logged-in Administrator. By exploiting this, an attacker can change the Administrator's email address and password via the '/auth/wp-login-redirect' endpoint, leading to a full account takeover. This requires the Administrator to visit a page controlled by the attacker.
Recommendations Update YOP Poll to version 7.0.11 or later.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85682

Affected Products

Yop Poll