Description

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

INFO

Published Date :

2025-05-15T20:07:18.942Z

Last Modified :

2025-05-16T20:40:18.451Z

Source :

WPScan
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8851 vulnerability.

Vendors Products
Codepeople
  • Polls Cp
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-8851.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact