๐Ÿ” CVE Alert

CVE-2026-14840

UNKNOWN 0.0

YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.

Vendor unknown
Product yop poll
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown yop poll

Be the first to know when new unknown vulnerabilities affecting unknown yop poll are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / YOP Poll
7.0.0 < 7.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fc810ca2-3f27-414d-b94a-68842925b7c6/

Credits

Melina Lentini (M3l3n) WPScan