Hmm, this was in 16 Oct, 2025, all the XSS reported to me so far has been fixed. I am not sure if patchstack reported version is correct.
Anyway, I am using AI to rewrite the plugin to be more modern, maybe you can help test it https://github.com/lesterchan/wp-polls/archive/refs/heads/master.zip
Thread Starter
stopps
(@stopps)
Hi Lester,
Thanks for the response, I’ll schedule some time to take a look at the new AI version and do some testing.
Just so you are aware, Wordfence are now also reporting the new issue: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-polls/wp-polls-2773-authenticated-administrator-stored-cross-site-scripting
They are classifying it as low risk as it is an Administrator+ exploit:
“The WP-Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.77.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.”
I’m not sure how this can be classified as a vulnerability if someone has chosen to disabled unfiltered_html, but you’ll probably want to issue a patch just to avoid the plugin directory restricting the plugin’s access.
All the best,