CVE-2026-14840 PUBLISHED

YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing

Assigner: WPScan
Reserved: 06.07.2026 Published: 01.08.2026 Updated: 01.08.2026

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.

Product Status

Vendor Unknown
Product YOP Poll
Versions Default: unaffected
  • affected from 7.0.0 to 7.0.6 (excl.)

Credits

  • Melina Lentini (M3l3n) finder
  • WPScan coordinator

References

Problem Types

  • CWE-290 Authentication Bypass by Spoofing CWE