SB2020041507 - Improper Authentication in Responsive Poll plugin for WordPress
Published: April 15, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2020-11673)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the usage of the callback "wp_ajax_nopriv" function in "Includes/Total-Soft-Poll-Ajax.php" for sensitive operations. A remote attacker can bypass authentication process and delete, clone, or view a hidden poll.
Remediation
Install update from vendor's website.