Poll Maker <= 5.7.7 - Unauthenticated Race Condition to Multi-Vote
Strategic Overview
<= 5.7.7CVE-2025-47545Vulnerability Overview
The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to a Race Condition in all versions up to, and including, 5.7.7. This is due to the plugin not properly restricting a user's ability to fill out a poll multiple times.. This makes it possible for unauthenticated attackers to fill out a poll multiple times.
Technical Analysis
REMEDIATION: Update to version 5.7.8, or a newer patched version --- IDENTIFIER: CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')) The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C