Junglewise Threat Intelligence

CVE-2026-39651: TotalSuite Total Poll Lite Missing Authorization in Access Control

CVE-2026-39651 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Executive brief

Total Poll Lite is a WordPress plugin used to create and manage polls on websites. A security flaw in the plugin's access control settings allows users with low-level accounts (such as contributors) to bypass intended restrictions. This could lead to unauthorized access to sensitive information or administrative functions within the polling system.

Technical details

A missing authorization vulnerability (CWE-862) exists in TotalSuite Total Poll Lite through version 4.12.0. The flaw stems from incorrectly configured access control security levels within the plugin's logic. An authenticated attacker with 'Contributor' level privileges can exploit this to perform actions or access data that should be restricted to higher-privileged users. The attack is reachable over the network without user interaction. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates beyond version 4.12.0.

Affected products

  • TotalSuite Total Poll Lite <= 4.12.0

Timeline

  • 2026-01-16: other: Vulnerability reported by researcher Doan Dinh Van
  • 2026-02-15: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References