VYPR
Medium severity6.5NVD Advisory· Published Apr 8, 2026· Updated Apr 29, 2026

CVE-2026-39651

CVE-2026-39651

Description

Missing Authorization vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a through <= 4.12.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated broken access control in Total Poll Lite ≤4.12.0 allows attackers to exploit incorrectly configured access restrictions.

Root

Cause

The Total Poll Lite WordPress plugin versions up to and including 4.12.0 suffer from a missing authorization vulnerability. The flaw stems from an incorrect configuration of access control security levels, where privilege checks or nonce tokens are absent in certain functions. This allows any unauthenticated visitor to perform actions that should be reserved for higher-privileged users [1].

Attack

Vector

No authentication is required to trigger the vulnerability. An attacker can send crafted requests to the plugin's endpoints, bypassing intended permission checks. The issue is part of a class of mass-exploit vulnerabilities often used in campaigns that target thousands of WordPress sites simultaneously, regardless of their size or popularity [1].

Impact

Successful exploitation enables an attacker to execute higher-privileged actions without proper authorization. Depending on the specific function that lacks access control, this could lead to unauthorized data modification, content manipulation, or other administrative capabilities that compromise site integrity [1]. The CVSS v3 score of 6.5 reflects the medium severity of such broken access control flaws.

Mitigation

The vendor recommends updating Total Poll Lite to a version newer than 4.12.0. For those unable to update immediately, consulting a hosting provider or web developer for additional security measures is advised. The vulnerability is not yet known to be listed on CISA's Known Exploited Vulnerabilities (KEV) catalog [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.