CVE-2024-12575: Poll Maker – Versus Polls, Anonymous Polls, Image Polls <= 5.8.9 - Unauthenticated Basic Information Exposure
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 5.8.9 via the 'aysfinishpoll' AJAX action. This makes it possible for unauthenticated attackers to retrieve admin email information which is exposed in the poll response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12575?
CVE-2024-12575 is classified as a basic information exposure vulnerability that can lead to unauthorized retrieval of sensitive admin data.
How do I fix CVE-2024-12575?
To fix CVE-2024-12575, update the Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin to version 5.9.0 or later.
Who is affected by CVE-2024-12575?
CVE-2024-12575 affects all versions of the Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin up to and including version 5.8.9.
What kind of data can be exposed due to CVE-2024-12575?
Due to CVE-2024-12575, unauthenticated attackers can potentially retrieve the admin email address.
When was CVE-2024-12575 discovered?
CVE-2024-12575 was disclosed as a vulnerability without a specific publicly available date in the provided metadata.