CVE-2026-85682
8.8 HIGHPublished 2026-09-24 · Updated 2026-09-24
AI risk analysis
- Summary
- The flaw is an Origin Validation Error in the YOP Poll plugin for WordPress, allowing unauthenticated attackers to steal a REST nonce and change the Administrator's email and password, leading to full account takeover.
- Exploitability
- Exploitation requires the Administrator to open an attacker-controlled page, making it moderately hard to exploit.
- Blast radius
- If exploited, the impact is severe, as it results in full account takeover for the Administrator's account.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 7.0.11 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-346
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-15372
- HIGHCVE-2026-15979
- HIGHCVE-2026-16036
- HIGHCVE-2026-16605
- HIGHCVE-2026-16736
- HIGHCVE-2026-6147
- HIGHCVE-2026-7693
- CRITICALCVE-2026-82843
Related by shared AI tags and CWE weakness class. Browse the full archive.