{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/yop-poll--7.0.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:yop-poll:yop_poll:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-85682"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["YOP Poll (\u003c= 7.0.10)"],"_cs_severities":["medium"],"_cs_tags":["wordpress","plugin","account-takeover","vulnerability"],"_cs_type":"threat","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe YOP Poll plugin for WordPress is vulnerable to an origin validation error (CVE-2026-85682) in all versions up to and including 7.0.10. The vulnerability stems from the plugin's improper use of the postMessage() API, which transmits a wp_rest nonce to the window.opener object using a wildcard targetOrigin. By exploiting this, an unauthenticated attacker can orchestrate a cross-origin attack against a logged-in Administrator. If an Administrator is induced to visit an attacker-controlled website, the attacker can intercept the transmitted nonce. With this REST nonce, the attacker gains the ability to make authenticated requests on behalf of the Administrator, specifically allowing them to modify administrative credentials, change the associated email address, and achieve a full account takeover of the WordPress instance. This vulnerability highlights the risks associated with improper cross-window communication in web plugins.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker hosts a malicious webpage containing a crafted JavaScript payload.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a phishing campaign or uses social engineering to lure an authenticated WordPress Administrator to the malicious webpage.\u003c/li\u003e\n\u003cli\u003eThe malicious webpage opens a new window or tab pointing to the target WordPress site's YOP Poll component.\u003c/li\u003e\n\u003cli\u003eThe YOP Poll plugin executes, sending a message containing the sensitive 'wp_rest' nonce via postMessage() to the opener.\u003c/li\u003e\n\u003cli\u003eThe attacker's malicious script intercepts the window.opener.postMessage event due to the wildcard origin configuration.\u003c/li\u003e\n\u003cli\u003eAttacker extracts the valid 'wp_rest' nonce from the message object.\u003c/li\u003e\n\u003cli\u003eAttacker uses the stolen nonce to authenticate REST API calls directed at the WordPress backend.\u003c/li\u003e\n\u003cli\u003eAttacker updates the Administrator's user profile, changing the email address and password to finalize account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full administrative account takeover. This gives the attacker complete control over the WordPress instance, enabling them to modify content, install malicious plugins, exfiltrate database contents, or deploy additional malware. The scope is limited to WordPress installations utilizing YOP Poll version 7.0.10 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the remediation of CVE-2026-85682 by updating the YOP Poll plugin to the latest version patched by the vendor. Ensure that administrative users are encouraged to maintain session hygiene and avoid navigating to untrusted external sites while holding an active, elevated session in the WordPress dashboard.\u003c/p\u003e\n","date_modified":"2026-09-24T10:46:42Z","date_published":"2026-09-24T10:46:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-yop-poll-nonce-theft/","summary":"The YOP Poll plugin for WordPress, in versions up to 7.0.10, exposes REST nonces via postMessage to window.opener, enabling attackers to perform unauthorized administrative actions including account takeover.","title":"Account Takeover via Origin Validation Error in YOP Poll WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-yop-poll-nonce-theft/"}],"language":"en","title":"CraftedSignal Threat Feed - YOP Poll (\u003c= 7.0.10)","version":"https://jsonfeed.org/version/1.1"}