CVE-2020-11673: Total-Soft Responsive Poll

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php for sensitive operations.

Affected products

  • Total-Soft Responsive Poll: up to and including 1.3.4

Published 2020-04-13. Last modified 2026-06-17.