Vulnerability Details CVE-2022-1581
The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 15.4%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2022-1581
-
cpe:2.3:a:wp-polls_project:wp-polls:2.70
-
cpe:2.3:a:wp-polls_project:wp-polls:2.71
-
cpe:2.3:a:wp-polls_project:wp-polls:2.72
-
cpe:2.3:a:wp-polls_project:wp-polls:2.73
-
cpe:2.3:a:wp-polls_project:wp-polls:2.73.1
-
cpe:2.3:a:wp-polls_project:wp-polls:2.73.2
-
cpe:2.3:a:wp-polls_project:wp-polls:2.73.3
-
cpe:2.3:a:wp-polls_project:wp-polls:2.73.4
-
cpe:2.3:a:wp-polls_project:wp-polls:2.73.5
-
cpe:2.3:a:wp-polls_project:wp-polls:2.73.6
-
cpe:2.3:a:wp-polls_project:wp-polls:2.73.7
-
cpe:2.3:a:wp-polls_project:wp-polls:2.73.8
-
cpe:2.3:a:wp-polls_project:wp-polls:2.74
-
cpe:2.3:a:wp-polls_project:wp-polls:2.74.1
-
cpe:2.3:a:wp-polls_project:wp-polls:2.75
-
cpe:2.3:a:wp-polls_project:wp-polls:2.75.1
-
cpe:2.3:a:wp-polls_project:wp-polls:2.75.2
-
cpe:2.3:a:wp-polls_project:wp-polls:2.75.3
-
cpe:2.3:a:wp-polls_project:wp-polls:2.75.4
-
cpe:2.3:a:wp-polls_project:wp-polls:2.75.5
-
cpe:2.3:a:wp-polls_project:wp-polls:2.75.6