CVE-2013-1400: Cardozatechnologies WordPress Poll

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.

Affected products

Published 2020-02-13. Last modified 2026-06-16.