CVE-2020-24315: WordPress Poll Project WordPress Poll

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.

Affected products

Published 2020-08-26. Last modified 2026-06-17.