First published: Tue Aug 27 2019(Updated: )
The cp-polls plugin before 1.0.5 for WordPress has XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople CP Polls | <1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-9346 is rated as a medium severity vulnerability due to the potential for cross-site scripting (XSS).
To fix CVE-2015-9346, update the cp-polls plugin to version 1.0.5 or later.
CVE-2015-9346 allows attackers to execute malicious scripts in the browser of users visiting the site, potentially compromising user data.
CVE-2015-9346 affects the cp-polls plugin on WordPress sites running versions prior to 1.0.5.
Anyone using the cp-polls plugin for WordPress versions below 1.0.5 is vulnerable to CVE-2015-9346.