CVE-2016-20067 PUBLISHED

WordPress CP Polls 1.0.8 Cross-Site Request Forgery

Assigner: VulnCheck
Reserved: 14.06.2026 Published: 15.06.2026 Updated: 15.06.2026

WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attackers can craft malicious HTML pages that execute unwanted poll operations when administrators visit the page while logged in.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L
CVSS Score: 5.3

Product Status

Vendor dwbooster
Product CP Polls
Versions
  • Version 1.0.8 is affected

Credits

  • Joaquin Ramirez Martinez [ i0akiN SEC-LABORATORY ] finder

References

Problem Types

  • Cross-Site Request Forgery (CSRF) CWE