CVE-2020-24315: WordPress Poll Project WordPress Poll
High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.
Affected products
- WordPress Poll Project WordPress Poll: up to and including 36.0
Published 2020-08-26. Last modified 2026-06-17.