nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20062 CVE-2016-20062
HIGH
Simply Poll 1.4.1 Plugin for WordPress SQL Injection
Record summary
CVE-2016-20062 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the 'pollid' POST parameter. Attackers can send requests to the admin-ajax.php endpoint with the 'spAjaxResults' action and malicious 'pollid' values to execute arbitrary SQL queries and read sensitive data from the WordPress database.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 9, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Simply PollBrowse Ollie Armstrong / Simply Poll | CVE List | 1.4.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Simply Poll 1.4.1 - SQL InjectionExploitDB exploitby TAD GROUPNot analyzed1 file
References
5Official Product Homepageproduct
https://tad.group/ Official Product Homepageproduct
https://wordpress.org/plugins/simply-poll ExploitDB-40971exploit
https://www.exploit-db.com/exploits/40971 VulnCheck Advisory: Simply Poll 1.4.1 Plugin for WordPress SQL InjectionThird-party advisory
https://www.vulncheck.com/advisories/simply-poll-plugin-for-wordpress-sql-injection