WordPress TS Poll plugin < 2.4.0 contains a SQL injection caused by lack of sanitization and escaping of a parameter before using it in a SQL statement, letting attackers perform SQL injection attacks, exploit requires admin privileges.
id: CVE-2024-8625
info:
name: WordPress TS Poll < 2.4.0 - SQL Injection
author: riteshs4hu
se
...