CVE-2025-3880 Information

Description

The Poll Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to unauthorized modification of data due to a misconfigured capability check on several functions in all versions up to and including 19.9.0. This makes it possible for authenticated attackers with Contributor-level access and above to change the email address for the account connection and disconnect the plugin. Previously created content will still be displayed and functional if the account is disconnected.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Reference

https://plugins.trac.wordpress.org/browser/social-polls-by-opinionstage/trunk/plugin.php https://plugins.trac.wordpress.org/browser/social-polls-by-opinionstage/trunk/src/Modules/Admin.php https://plugins.trac.wordpress.org/changeset/3310848/ https://www.wordfence.com/threat-intel/vulnerabilities/id/ba86268a-7bd6-40ed-9af6-29409245675d?source=cve

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

CNNVD-202506-1989 (Published: 2025-06-17)

Share on: