CVE-2026-14840
N/A
N/A
Summary
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | YOP Poll | 7.0.0 < 7.0.6 | affected |
Weaknesses
- CWE-290 Authentication Bypass by Spoofing
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.