← Back to search

CVE-2026-85682

8.8 HIGH

Published 2026-09-24 · Updated 2026-09-24

AI risk analysis

Summary
The flaw is an Origin Validation Error in the YOP Poll plugin for WordPress, allowing unauthenticated attackers to steal a REST nonce and change the Administrator's email and password, leading to full account takeover.
Exploitability
Exploitation requires the Administrator to open an attacker-controlled page, making it moderately hard to exploit.
Blast radius
If exploited, the impact is severe, as it results in full account takeover for the Administrator's account.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 7.0.11 or later.
auth-bypasswebwordpress

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-346

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.