CVE-2025-26971: WordPress Poll Maker <= 5.6.5 - SQL Injection vulnerability
Published Feb 25, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Poll Maker poll-maker allows Blind SQL Injection.This issue affects Poll Maker: from n/a through <= 5.6.5.
Affected Software
3 affected components
ays-pro Poll Maker<=5.6.5
WordPress Poll Maker<=5.6.5
ays-pro Poll Maker Wordpress<5.6.6
Remediation
Information
Update the WordPress Poll Maker wordpress plugin to the latest available version (at least 5.6.6).
Event History
Feb 25, 2025
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26971?
CVE-2025-26971 is rated as a high severity vulnerability due to its potential for exploitation via blind SQL injection.
2
How do I fix CVE-2025-26971?
To fix CVE-2025-26971, upgrade the ays-pro Poll Maker plugin to the latest version beyond 5.6.5.
3
What types of attacks can CVE-2025-26971 facilitate?
CVE-2025-26971 can facilitate SQL injection attacks, allowing attackers to manipulate database queries.
4
Which versions are affected by CVE-2025-26971?
CVE-2025-26971 affects ays-pro Poll Maker versions up to and including 5.6.5.
5
Is CVE-2025-26971 specific to any platform?
Yes, CVE-2025-26971 is specifically related to the ays-pro Poll Maker plugin used in WordPress.