CVE-2026-85682
Deferred Deferred - Pending Action

YOP Poll WordPress Plugin Origin Validation Error

Vulnerability report for CVE-2026-85682, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: Wordfence

Description

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it possible for unauthenticated attackers to steal a REST nonce scoped to a logged-in Administrator and use it to change the Administrator's email address and password, resulting in full account takeover. The Administrator must open an attacker-controlled page in order to exploit this vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-25
AI Q&A
2026-09-24
EPSS Evaluated
2026-09-24
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yop_poll yop_poll to 7.0.10 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The YOP Poll WordPress plugin has an Origin Validation Error in versions up to 7.0.10. It sends a wp_rest nonce via postMessage() with a wildcard targetOrigin, allowing unauthenticated attackers to steal the nonce from an admin. This nonce can then be used to change the admin's email and password, leading to full account takeover if the admin visits a malicious page.

Detection Guidance

Check if the YOP Poll plugin is installed and its version is up to 7.0.10. Look for suspicious REST nonce usage or postMessage events in browser developer tools. Review WordPress logs for unauthorized email or password changes.

Impact Analysis

If you use the YOP Poll plugin on your WordPress site, an attacker could take over your admin account. This means they could lock you out, modify your site, or perform other administrative actions without your consent.

Compliance Impact

This vulnerability could lead to unauthorized account takeover, potentially exposing sensitive user data. For GDPR, this may result in non-compliance due to unauthorized access to personal data. For HIPAA, it could risk protected health information exposure if user accounts with such data are compromised.

Mitigation Strategies

Update the YOP Poll plugin to the latest version. Disable the plugin if an update is unavailable. Monitor for unauthorized admin account changes and revoke suspicious sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85682. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart