logo

CVE-2016-20066: WordPress CP Polls Persistent XSS via File Upload

ID: 59bf020d-122a-5d58-95d1-3fe1c21e0ad8

STIX ID: report--59bf020d-122a-5d58-95d1-3fe1c21e0ad8

Feed Name: CosmicBytez Labs

Threat Score
55/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

...
...

A persistent XSS vulnerability (CVE-2016-20066) in the WordPress CP Polls plugin v1.0.8 lets authenticated low-privilege users upload files with embedded JavaScript that execute in administrator browsers, enabling session hijacking, credential theft, and administrative actions; the report provides technical details, a CVSS 3.1 vector (7.2), affected versions, and immediate and long-term remediation steps (disable plugin, audit uploads, rotate credentials, apply CSP/WAF).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.