gist.github.com
https://gist.github.com/pak0s/05a0e517aeff4b1422d1a93f59718459 CVE-2020-11673
CRITICAL
Record summary
CVE-2020-11673 has a selected CVSS score of 9.8 (critical).
Description
An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php for sensitive operations.
Description source: CVE List
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-11673 wordpress.org
https://wordpress.org/plugins/poll-wp