{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/yop-poll-7.0.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":5.3,"id":"CVE-2026-14840"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["YOP Poll (7.0.5)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["YOP Poll"],"content_html":"\u003cp\u003eCVE-2026-14840 affects the YOP Poll plugin (version 7.0.5) for WordPress, enabling unauthorized manipulation of poll results. The vulnerability arises from improper validation of the client's IP address when determining voting eligibility. An attacker can bypass per-IP rate limiting by injecting arbitrary IP addresses into the X-Forwarded-For HTTP header, causing the application to treat each request as originating from a unique, previously uncounted user. This vulnerability allows for the automated submission of multiple votes, potentially skewing public perception or poll outcomes. A functional proof-of-concept exploit was released on 2026-08-13, significantly lowering the barrier for exploitation. Defenders should monitor for anomalous spikes in voting activity from single sources and validate IP-based restrictions against header-based spoofing.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target website utilizing the YOP Poll WordPress plugin version 7.0.5.\u003c/li\u003e\n\u003cli\u003eAttacker inspects the polling mechanism to determine the endpoint processing vote submissions.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a series of HTTP POST requests directed at the poll submission endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a custom 'X-Forwarded-For' header in each request with unique or spoofed IP address values.\u003c/li\u003e\n\u003cli\u003eThe YOP Poll plugin processes the request and incorrectly trusts the 'X-Forwarded-For' value over the source IP for rate-limiting checks.\u003c/li\u003e\n\u003cli\u003eThe backend database, 'wp_yoppoll_votes', records each request as a legitimate vote from a new user.\u003c/li\u003e\n\u003cli\u003eAttacker repeats the process to accumulate a large number of votes, effectively rigging the poll results.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to bypass business logic controls, leading to the integrity compromise of poll results. While the impact is primarily service-level manipulation rather than data exfiltration or system compromise, it directly affects the trustworthiness of user engagement features deployed across WordPress websites. Organizations relying on this plugin for public sentiment analysis or high-stakes voting should consider the risk of automated manipulation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement request logging for the 'X-Forwarded-For' header in web application firewalls or load balancers to detect irregular patterns of IP rotation.\u003c/li\u003e\n\u003cli\u003ePatch the YOP Poll plugin to the latest version as soon as a fix is available from the vendor.\u003c/li\u003e\n\u003cli\u003eReview web server configurations to ensure that 'X-Forwarded-For' headers are sanitized or trusted only from verified proxy ranges.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T00:27:22Z","date_published":"2026-08-13T00:27:22Z","id":"https://feed.craftedsignal.io/briefs/2026-08-yop-poll-limit-bypass/","summary":"A publicly available exploit targets CVE-2026-14840, a vulnerability in the YOP Poll plugin (v7.0.5) that allows attackers to bypass voting rate limits by spoofing IP addresses via the X-Forwarded-For HTTP header.","title":"Voting Limit Bypass in YOP Poll Plugin via X-Forwarded-For Spoofing","url":"https://feed.craftedsignal.io/briefs/2026-08-yop-poll-limit-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - YOP Poll (7.0.5)","version":"https://jsonfeed.org/version/1.1"}