CVE-2026-14840
YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.
| Vendor | unknown |
| Product | yop poll |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown yop poll
Be the first to know when new unknown vulnerabilities affecting unknown yop poll are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / YOP Poll
7.0.0 < 7.0.6
References
Credits
Melina Lentini (M3l3n) WPScan