Input validation vulnerability in WP-Polls 2.70

The WP-Polls plugin for WordPress is vulnerable to a type of attack known as Stored Cross-Site Scripting. This vulnerability affects versions of the plugin up to and including 2.70. The vulnerability is caused by the plugin not properly sanitizing and escaping user input, which makes it possible for unauthenticated attackers to inject malicious web scripts into pages. These scripts will execute each time a user visits an injected page.

Detected in:

WP-Polls fixed vulnerable versions: >= * <= 2.70

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.