Showing 1 vulnerability on this page for Poll Maker by AYS – Versus Polls, Anonymous Polls, Image Polls

Signals CISA KEV Ransomware Nuclei
ays-pro vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Poll Maker by AYS <= 6.3.7 - Authenticated (Subscriber+) Sensitive Information Exposure in 'ays_poll_get_user_information' AJAX Action

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 6.3.7. This is due to insufficient access controls on the 'ays_poll_get_user_information' AJAX action, which serializes and returns the complete WP_User object — including the user_pass (bcrypt password hash), user_email, user_login, user_registered, roles, and all capabilities — without any nonce verification or capability check beyond

CWE-200May 29, 2026
CVSS4.3v3.1EPSS0.283%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX