Sploitus

CVE-2026-14840

1 known exploit for CVE-2026-14840

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.

Affected products
Yop Poll
CVSS 3.1
5.3 MEDIUM
EPSS
0.2% (11th percentile)
Weakness
CWE-290
NVD status
Received
Published
2026-08-01
CVE-2026-14840 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-14840

Proof-of-concept code and exploit modules indexed by Sploitus