CVE-2026-14840
Received Received - Intake

YOP Poll Plugin Origin IP Validation Bypass

Vulnerability report for CVE-2026-14840, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yop_poll plugin to 7.0.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the YOP Poll WordPress plugin before version 7.0.6. It fails to validate the origin IP address of connections and instead relies on client-controlled forwarding headers to enforce vote restrictions per IP. This allows attackers to bypass the vote limit and cast unlimited votes on public polls without authentication.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the YOP Poll plugin versions before 7.0.6. Check server access logs for repeated votes from the same IP address or unusual voting patterns. No specific commands are provided in the context.

Impact Analysis

If you use the YOP Poll plugin before version 7.0.6, attackers could manipulate poll results by submitting unlimited votes. This undermines the integrity of your polls and could skew data or opinions presented to users.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it involves a WordPress plugin's vote restriction bypass rather than data protection or privacy issues.

Mitigation Strategies

Update the YOP Poll WordPress plugin to version 7.0.6 or later to address the origin IP validation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14840. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart