High severity7.2NVD Advisory· Published Apr 19, 2024· Updated Apr 8, 2026
CVE-2024-3600
CVE-2024-3600
Description
The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the ays_poll_maker_quick_start AJAX action in addition to insufficient escaping and sanitization in all versions up to, and including, 5.1.8. This makes it possible for unauthenticated attackers to create quizzes and inject malicious web scripts into them that execute when a user visits the page.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/fec015e1-7f64-4917-a242-90bd1135f680nvdThird Party Advisory
- plugins.trac.wordpress.org/changesetnvdProduct
News mentions
0No linked articles in our index yet.