CVE detail
CVE-2020-24315 — CVE-2020-24315
Published 2020-08-26 · Modified 2026-06-17 · Vendor wordpress_poll_project · Product wordpress_poll · Source nvd
HIGH
severity
CVSS-derived band
0.0204
EPSS probability
exploitation probability, 30d
79.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References