CVE-2025-46466
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 352
Summary
CVE-2025-46466 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Modern Polls, a plugin used for creating polls in WordPress websites. This issue enables attackers to inject Stored Cross-Site Scripting (XSS) codes into affected polls, potentially stealing user data or taking control of their sessions when they interact with the polls. Modern Polls versions from n/a to 1.0.10 are susceptible to this vulnerability. It is essential for users to update their Modern Polls plugin to the latest, secure version to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.