CVE-2025-68588

8.1

TotalSoft · TS Poll (poll-wp)

A missing authorization vulnerability in the WordPress TS Poll plugin allows authenticated users with low privileges to exploit incorrect access control security settings.

Executive summary

The TS Poll plugin for WordPress contains a missing authorization flaw that permits low-privileged users to manipulate access controls, posing a significant risk to site integrity.

Vulnerability

The vulnerability is identified as a missing authorization issue (CWE-862) within the plugin. Based on the CVSS vector, this flaw requires the attacker to have low-level privileges (PR:L) to successfully execute unauthorized actions.

Business impact

This vulnerability allows authenticated users to perform actions they are not authorized to access, which can lead to unauthorized modification of poll data or configuration settings. With a CVSS score of 8.1, the issue represents a high-severity risk that could compromise the integrity of site content and administrative workflows if left unaddressed.

Remediation

Immediate Action: Since no specific patch version is currently confirmed, administrators should monitor the official WordPress plugin repository for security updates and apply them as soon as they are released.

Proactive Monitoring: Review WordPress user activity logs for suspicious configuration changes or unauthorized modifications to poll settings by low-privileged accounts.

Compensating Controls: Implement a Web Application Firewall (WAF) to filter malicious requests targeting the plugin and consider restricting access to the administrative dashboard for non-privileged users until a fix is deployed.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score of 8.1, this vulnerability poses a credible risk to the integrity of the affected WordPress environment. Security teams must prioritize monitoring for vendor updates and be prepared to update the TS Poll plugin immediately upon the release of a patch to prevent unauthorized access control bypass.

Sources

Originally found and disclosed by daroo | Patchstack Bug Bounty Program, per the CVE Program record.