CVE-2021-34635: Poll Maker <= 3.2.8 - Reflected Cross-Site Scripting
Published Aug 2, 2021
·Updated
The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/admin/partials/settings/poll-maker-settings.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.8.
Affected Software
1 affected component
ays-pro Poll Maker Wordpress<=3.2.8
Remediation
Information
Update plugin to version 3.2.9 or newer.
Event History
Aug 2, 2021
CVE Published
via MITRE·08:39 PM
Data Sourced
via MITRE·08:39 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Poll Maker WordPress plugin vulnerability?
The vulnerability ID for the Poll Maker WordPress plugin vulnerability is CVE-2021-34635.
2
What is the severity of CVE-2021-34635?
The severity of CVE-2021-34635 is medium.
3
How does the Poll Maker WordPress plugin vulnerability work?
The Poll Maker WordPress plugin vulnerability allows attackers to inject arbitrary web scripts via the 'mcount' parameter in the poll-maker-settings.php file.
4
Which version of the Poll Maker WordPress plugin is affected by CVE-2021-34635?
Versions up to and including 3.2.8 of the Poll Maker WordPress plugin are affected by CVE-2021-34635.
5
How can I fix the Poll Maker WordPress plugin vulnerability?
To fix the Poll Maker WordPress plugin vulnerability, update to a version higher than 3.2.8.