CVE-2025-24577: Ays-Pro Poll Maker

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Poll Maker: from n/a through <= 5.5.0.

Affected products

  • Ays-Pro Poll Maker: before 5.5.1 (fixed in 5.5.1)

Published 2025-04-17. Last modified 2026-06-17.