CVE-2024-56277 Details
Description
Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: from n/a through < 5.5.5.
A vulnerability exists in the WordPress Poll Maker plugin, specifically in versions prior to 5.5.5, due to improper encoding or escaping of output. This flaw allows for content injection, where a malicious actor could insert their own content into the pages and posts of a WordPress site. Such an injection could be exploited to add phishing pages, for example.
Users of the WordPress Poll Maker plugin should update to version 5.5.5 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ays-pro poll maker | < 5.5.5 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | CVE Modified | [email protected] |
| Jun 9, 2025 | Initial Analysis | [email protected] |
| Jan 21, 2025 | New CVE Received | [email protected] |