WP脆弱性ウォッチ脆弱性データ 2026年8月28日 時点

CVE-2020-11673

TS Poll – Survey, Versus Poll, Image Poll, Video Poll に報告された脆弱性

緊急深刻度
9.8CVSS 3.1
1.3.4修正されたバージョン
3.5%30日以内に悪用される確率
今後30日以内に悪用される確率は 3.5% と推定されています(EPSS)。

概要

An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php for sensitive operations.

CWE: CWE-306 / 公開 2020年4月13日 / 最終更新 2026年6月17日

影響を受けるバージョン

対処方法

TS Poll – Survey, Versus Poll, Image Poll, Video Poll を 1.3.4 以降に更新してください。これで本脆弱性は解消します。

この脆弱性は実証コードが公開されています。攻撃に利用されやすい状態のため、優先して対応してください。

TS Poll – Survey, Versus Poll, Image Poll, Video Poll の他の脆弱性を見る →

あなたのサイトは大丈夫ですか?

URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。

30秒で無料診断する

参照