SecAlerts
poll maker logo

poll maker

Security Risk Profile

30
/100
low

Security Risk Score

Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 19, 2024 to present

10
Total CVEs
2
Critical+High
0
Exploited
2
Unpatched

Threat Assessment

Avg CVSS
5.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
30/100
low

Severity Distribution

Critical
0
High
2
Medium
8
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
3
2
SQL Injection
2
3
Infoleak
1

Most Affected Products

1. ays-pro Poll Maker Wordpress7
2. Poll Maker Versus Polls, Anonymous Polls, Image Polls4
3. Poll Maker Poll Maker3
4. WordPress Poll Maker plugin2
5. Poll Maker WordPress plugin1

Recent Vulnerabilities

See more →
CVE-2025-12620
CVSS 4.9medium

Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 6.0.7 - Authenticated (Administrator+) SQL Injection via `filterbyauthor` Parameter

11/13/2025🔧 No Patch
CVE-2024-12575
CVSS 5.3medium

Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.8.9 - Unauthenticated Basic Information Exposure

8/16/2025🔧 No Patch
CVE-2024-13602
CVSS 4.8medium

Poll Maker < 5.5.4 - Admin+ Stored XSS

3/16/2025🔧 No Patch
CVE-2024-56295
CVSS 6.5medium

WordPress Poll Maker plugin <= 5.5.6 - Broken Access Control vulnerability

1/15/2025
CVE-2023-45766
CVSS 5.3medium

WordPress Poll Maker plugin <= 4.7.1 - Broken Access Control vulnerability

1/2/2025
CVE-2023-50904
CVSS 5.3medium

WordPress Poll Maker plugin <= 4.8.0 - Broken Access Control vulnerability

12/9/2024
CVE-2024-9462
CVSS 5.5EPSS 0%medium

Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.4.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Poll Settings

10/26/2024🔧 No Patch
CVE-2024-9475
CVSS 7.2EPSS 0%high

Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.4.6 - Authenticated (Administrator+) SQL Injection via Order_by Parameter

10/26/2024🔧 No Patch
CVE-2024-3601
CVSS 5.3EPSS 0%medium

Poll Maker – Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Email Enumeration

5/2/2024🔧 No Patch
CVE-2024-3600
CVSS 7.2EPSS 0%high

Poll Maker – Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting

4/19/2024🔧 No Patch

Monitor poll maker in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.