Executive brief
Simply Poll is a WordPress plugin used to create and display polls on websites. A security flaw in this plugin allows unauthenticated attackers to access the site's underlying database. This could lead to the theft of sensitive information, including user credentials, site configurations, and customer data.
Technical details
An SQL injection vulnerability exists in the Simply Poll plugin (version 1.4.1 and below) for WordPress due to improper neutralization of the 'pollid' POST parameter. Unauthenticated attackers can exploit this by sending a crafted request to the 'admin-ajax.php' endpoint using the 'spAjaxResults' action. This allows for the execution of arbitrary SQL queries, enabling the extraction of sensitive data from the WordPress database. The vulnerability was publicly disclosed in 2016 and the plugin has since been closed/retired on the WordPress repository.
Affected products
- Ollie Armstrong Simply Poll 1.4.1 and earlier
Timeline
- 2016-12-21: disclosed: Vulnerability discovered and developer informed by TAD GROUP
- 2016-12-28: advisory: Public exploit released on Exploit-DB
- 2026-06-09: advisory: CVE record published/updated in NVD