Vendor
A publicly available exploit targets CVE-2026-14840, a vulnerability in the YOP Poll plugin (v7.0.5) that allows attackers to bypass voting rate limits by spoofing IP addresses via the X-Forwarded-For HTTP header.