CVE-2024-3601: Poll Maker – Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Email Enumeration
The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ayspollcreateauthor function in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to extract email addresses by enumerating them one character at a time.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3601?
CVE-2024-3601 has a medium severity due to the potential for unauthorized data access.
How do I fix CVE-2024-3601?
To fix CVE-2024-3601, update the Poll Maker – Best WordPress Poll Plugin to version 5.1.9 or later.
What impact does CVE-2024-3601 have on my WordPress site?
CVE-2024-3601 allows unauthenticated attackers to access and extract sensitive user data such as email addresses.
Which versions of the Poll Maker plugin are affected by CVE-2024-3601?
CVE-2024-3601 affects all versions of the Poll Maker plugin up to and including version 5.1.8.
Is there a patch available for CVE-2024-3601?
Yes, the vulnerability is patched in version 5.1.9 of the Poll Maker plugin.