Junglewise Threat Intelligence

CVE-2025-68081: Lester Chan WP-Polls cross site scripting in administrator interface

CVE-2025-68081 · Severity: medium · CVSS 5.9 · Published 2026-07-23

Executive brief

WP-Polls is a popular WordPress plugin used to create and manage polling systems on websites. A security vulnerability in versions up to 2.77.3 allows an attacker with administrative access to inject malicious scripts into the site's management interface. If another administrator views the affected page, these scripts could execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the WP-Polls plugin for WordPress (versions <= 2.77.3) due to improper neutralization of input during web page generation (CWE-79). The flaw allows a high-privileged attacker, such as an administrator, to inject malicious JavaScript into plugin settings or poll configurations. The attack requires a victim (typically another administrator) to interact with the affected administrative page for the script to execute in their browser context. This can lead to session hijacking or unauthorized configuration changes within the WordPress environment.

Affected products

  • Lester Chan WP-Polls <= 2.77.3

Timeline

  • 2026-07-23: disclosed: Date of NVD publication

References