CVE-2025-68594
8.1Opinion Stage · Poll, Survey & Quiz Maker Plugin
A missing authorization vulnerability in the Opinion Stage Poll, Survey & Quiz Maker plugin allows unauthenticated attackers to exploit incorrectly configured access controls.
Executive summary
The Opinion Stage Poll, Survey & Quiz Maker plugin is vulnerable to an authorization flaw that allows unauthenticated users to trigger unauthorized access control behaviors.
Vulnerability
The vulnerability is identified as a CWE-862 (Missing Authorization) flaw, which permits unauthenticated remote attackers to interact with the plugin without proper permission checks. This allows for the exploitation of incorrectly configured security levels within the affected software.
Business impact
The vulnerability carries a CVSS score of 8.1, indicating a high severity risk due to the lack of required authentication. Successful exploitation could lead to unauthorized configuration changes or the disruption of polling and survey services, potentially resulting in reputational damage and the loss of data integrity for user-facing interactive content.
Remediation
Immediate Action: Since a specific patch version is currently unknown, administrators should monitor the official WordPress plugin repository for updates and move to the latest version immediately upon release.
Proactive Monitoring: Review web server and WordPress application logs for unusual request patterns targeting the plugin's endpoints, particularly those originating from unauthenticated sources.
Compensating Controls: Implement Web Application Firewall (WAF) rules to restrict access to the plugin's administrative or survey-handling endpoints until a vendor-supplied update is verified and installed.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the absence of a confirmed patch, organizations currently running the Opinion Stage Poll, Survey & Quiz Maker plugin should exercise extreme caution. Evaluate the necessity of the plugin in the current environment and disable it if it is not critical to business operations until a secure version is confirmed by the vendor.