First published: Mon Oct 11 2021(Updated: )
The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action. While the result is not disclosed in the response, it is possible to use a timing attack to exfiltrate data such as password hash.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ays-pro Poll Maker | <3.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24651 is a vulnerability in the Poll Maker WordPress plugin before version 3.4.2 that allows unauthenticated users to perform SQL injection.
CVE-2021-24651 allows unauthenticated users to perform SQL injection via the ays_finish_poll AJAX action in the Poll Maker WordPress plugin.
CVE-2021-24651 has a severity rating of 7.5 out of 10, indicating a high severity.
An attacker can exploit CVE-2021-24651 by performing SQL injection attacks using the ays_finish_poll AJAX action to exfiltrate data, such as password hashes, through a timing attack.
Yes, a fix for CVE-2021-24651 is available in version 3.4.2 of the Poll Maker WordPress plugin.