Vulnerabilities > Wpdevart > Poll Survey Questionnaire AND Voting System > 1.2.8

DATE CVE VULNERABILITY TITLE RISK
2021-07-12 CVE-2021-24442 SQL Injection vulnerability in Wpdevart Poll, Survey, Questionnaire and Voting System
The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks
network
low complexity
wpdevart CWE-89
7.5