PatchSiren cyber security CVE debrief
CVE-2026-14840 YOP Poll CVE debrief
The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll. This vulnerability affects WordPress site administrators using the YOP Poll plugin. The plugin's failure to verify the origin IP address of incoming connections enables attackers to manipulate vote counts. As a result, defenders should prioritize updating the plugin to version 7.0.6 or later and review the plugin's configuration to ensure IP-based vote restrictions are properly enforced.
- Vendor
- YOP Poll
- Product
- YOP Poll WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-01
- Original CVE updated
- 2026-08-01
- Advisory published
- 2026-08-01
- Advisory updated
- 2026-08-01
Who should care
WordPress site administrators using the YOP Poll plugin, as well as security teams responsible for monitoring and responding to potential security incidents, should be aware of this vulnerability and take steps to address it. This includes verifying the version of the YOP Poll plugin installed on their WordPress sites, reviewing the plugin's configuration, and implementing compensating controls as needed. Additionally, operators of public polls created with the YOP Poll plugin should be aware of the potential for abuse and take steps to monitor and limit suspicious activity.
Technical summary
The YOP Poll WordPress plugin before 7.0.6 is vulnerable to IP spoofing attacks due to its reliance on client-controlled forwarding headers for IP validation. This allows unauthenticated attackers to bypass the vote limit and cast unlimited votes on public polls. The vulnerability is caused by the plugin's failure to validate the origin IP address of incoming connections, enabling attackers to manipulate vote counts. Defenders should update the plugin to version 7.0.6 or later and review the plugin's configuration to ensure IP-based vote restrictions are properly enforced.
Defensive priority
Low priority, as there is no evidence of active exploitation.
Recommended defensive actions
- Inventory and verify the YOP Poll WordPress plugin version
- Apply vendor remediation when available
- Monitor for suspicious vote activity
- Consider compensating controls for vote limiting
- Review the plugin's configuration to ensure that it is properly enforcing IP-based vote restrictions
- Track exceptions and retest remediated assets to ensure that the vulnerability has been properly addressed
- Verify that the YOP Poll plugin is properly configured and that compensating controls are in place to limit the impact of this vulnerability
Evidence notes
The evidence provided is limited; primary official records indicate a vulnerability in the YOP Poll WordPress plugin before version 7.0.6. The plugin does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction. This allows unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll. Defenders should verify the version of the YOP Poll plugin installed on their WordPress sites and ensure that it is updated to a version that addresses this vulnerability. Additionally, defenders should review the plugin's configuration and consider implementing compensating controls to limit the impact of this vulnerability.
Official resources
-
CVE-2026-14840 CVE record
CVE.org
-
CVE-2026-14840 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T07:16:31.060Z and has not been modified since then.