{"id":"CVE-2026-85682","published":"2026-09-24T09:17:08.797","lastModified":"2026-09-24T15:17:46.703","description":"The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-346"],"vendors":[],"products":[],"references":[{"url":"https://plugins.trac.wordpress.org/changeset/3690945/","tags":[]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/b3574182-1bda-49b2-aac7-60f862891b46?source=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is an Origin Validation Error in the YOP Poll plugin for WordPress, allowing unauthenticated attackers to steal a REST nonce and change the Administrator's email and password, leading to full account takeover.","exploitability":"Exploitation requires the Administrator to open an attacker-controlled page, making it moderately hard to exploit.","blast_radius":"If exploited, the impact is severe, as it results in full account takeover for the Administrator's account.","remediation":"Upgrade to version 7.0.11 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","wordpress"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:59:02.491Z"}}