CVE-2024-12115: Poll Maker <= 5.5.4 - Cross-Site Request Forgery to Poll Duplication
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on the duplicatepoll() function. This makes it possible for unauthenticated attackers to duplicate polls via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12115?
CVE-2024-12115 is classified as a serious Cross-Site Request Forgery vulnerability.
How do I fix CVE-2024-12115?
To fix CVE-2024-12115, upgrade the Poll Maker plugin to version 5.5.5 or later.
What versions are affected by CVE-2024-12115?
CVE-2024-12115 affects all versions of the Poll Maker plugin up to and including 5.5.4.
What is Cross-Site Request Forgery in the context of CVE-2024-12115?
Cross-Site Request Forgery in CVE-2024-12115 refers to the exploit that allows attackers to perform actions on behalf of an authenticated user without their consent due to missing nonce validation.
Who is the vendor associated with CVE-2024-12115?
The vendor associated with CVE-2024-12115 is Versus, the developer of the Poll Maker plugin.