SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14840

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The YOP Poll WordPress plugin prior to version 7.0.6 is vulnerable due to its failure to properly validate the origin IP address, relying instead on client-controlled forwarding headers for enforcing vote limits. This flaw allows unauthenticated attackers to circumvent the per-IP voting restrictions, enabling them to cast unlimited votes on public polls. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of vote manipulation.

CVE
CVE-2026-14840
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.