PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14840 YOP Poll CVE debrief

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction, allowing unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll. This vulnerability affects WordPress site administrators using the YOP Poll plugin. The plugin's failure to verify the origin IP address of incoming connections enables attackers to manipulate vote counts. As a result, defenders should prioritize updating the plugin to version 7.0.6 or later and review the plugin's configuration to ensure IP-based vote restrictions are properly enforced.

Vendor
YOP Poll
Product
YOP Poll WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-01
Original CVE updated
2026-08-01
Advisory published
2026-08-01
Advisory updated
2026-08-01

Who should care

WordPress site administrators using the YOP Poll plugin, as well as security teams responsible for monitoring and responding to potential security incidents, should be aware of this vulnerability and take steps to address it. This includes verifying the version of the YOP Poll plugin installed on their WordPress sites, reviewing the plugin's configuration, and implementing compensating controls as needed. Additionally, operators of public polls created with the YOP Poll plugin should be aware of the potential for abuse and take steps to monitor and limit suspicious activity.

Technical summary

The YOP Poll WordPress plugin before 7.0.6 is vulnerable to IP spoofing attacks due to its reliance on client-controlled forwarding headers for IP validation. This allows unauthenticated attackers to bypass the vote limit and cast unlimited votes on public polls. The vulnerability is caused by the plugin's failure to validate the origin IP address of incoming connections, enabling attackers to manipulate vote counts. Defenders should update the plugin to version 7.0.6 or later and review the plugin's configuration to ensure IP-based vote restrictions are properly enforced.

Defensive priority

Low priority, as there is no evidence of active exploitation.

Recommended defensive actions

  • Inventory and verify the YOP Poll WordPress plugin version
  • Apply vendor remediation when available
  • Monitor for suspicious vote activity
  • Consider compensating controls for vote limiting
  • Review the plugin's configuration to ensure that it is properly enforcing IP-based vote restrictions
  • Track exceptions and retest remediated assets to ensure that the vulnerability has been properly addressed
  • Verify that the YOP Poll plugin is properly configured and that compensating controls are in place to limit the impact of this vulnerability

Evidence notes

The evidence provided is limited; primary official records indicate a vulnerability in the YOP Poll WordPress plugin before version 7.0.6. The plugin does not validate the connection's origin IP address and instead trusts client-controlled forwarding headers when enforcing its per-IP vote restriction. This allows unauthenticated attackers to bypass the vote limit and cast unlimited votes on a public poll. Defenders should verify the version of the YOP Poll plugin installed on their WordPress sites and ensure that it is updated to a version that addresses this vulnerability. Additionally, defenders should review the plugin's configuration and consider implementing compensating controls to limit the impact of this vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T07:16:31.060Z and has not been modified since then.