CVE-2016-20066: WordPress CP Polls Persistent XSS via File Upload
ID: 59bf020d-122a-5d58-95d1-3fe1c21e0ad8
STIX ID: report--59bf020d-122a-5d58-95d1-3fe1c21e0ad8
Feed Name: CosmicBytez Labs
Threat Score
A persistent XSS vulnerability (CVE-2016-20066) in the WordPress CP Polls plugin v1.0.8 lets authenticated low-privilege users upload files with embedded JavaScript that execute in administrator browsers, enabling session hijacking, credential theft, and administrative actions; the report provides technical details, a CVSS 3.1 vector (7.2), affected versions, and immediate and long-term remediation steps (disable plugin, audit uploads, rotate credentials, apply CSP/WAF).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
