CPE
The YOP Poll plugin for WordPress, in versions up to 7.0.10, exposes REST nonces via postMessage to window.opener, enabling attackers to perform unauthorized administrative actions including account takeover.