CyberRota Analysis
AI-GeneratedThe YOP Poll WordPress plugin prior to version 7.0.6 is vulnerable due to its failure to properly validate the origin IP address, relying instead on client-controlled forwarding headers for enforcing vote limits. This flaw allows unauthenticated attackers to circumvent the per-IP voting restrictions, enabling them to cast unlimited votes on public polls. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of vote manipulation.
Original NVD Description
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.