Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Poll Maker
Ays Pro
Developer
6.0.9
Latest version
7,000
Installations
7 days ago
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Vulnerability history
0 present
22 fixed
8 Mitigation rules
Authenticated (Administrator+) SQL Injection via `filterbyauthor` Parameter vulnerability
<= 6.0.7
5 days ago
Cross Site Scripting (XSS) Vulnerability
<= 6.0.2
Sep 22, 2025
Unauthenticated Basic Information Exposure vulnerability
<= 5.8.9
Aug 15, 2025
Race Condition Vulnerability
<= 5.7.7
May 7, 2025
Admin+ Stored XSS vulnerability
< 5.5.4
Mar 18, 2025
SQL Injection vulnerability
<= 5.6.5
Feb 23, 2025
Broken Access Control vulnerability
<= 5.5.6
Jan 3, 2025
HTML Injection vulnerability
< 5.5.5
Jan 3, 2025
Broken Access Control vulnerability
<= 5.5.0
Dec 15, 2024
Cross-Site Request Forgery to Poll Duplication vulnerability
<= 5.5.4
Dec 6, 2024
Authenticated (Administrator+) Time-Based SQL Injection vulnerability
<= 5.4.6
Nov 8, 2024
Authenticated (Administrator+) SQL Injection vulnerability
<= 5.4.6
Oct 25, 2024
Authenticated (Administrator+) Stored Cross-Site Scripting vulnerability
<= 5.4.6
Oct 25, 2024
Missing Authorization to Unauthenticated Email Enumeration vulnerability
<= 5.1.8
Apr 19, 2024
Missing Authorization to Unauthenticated Stored Cross-Site Scripting vulnerability
<= 5.1.8
Apr 19, 2024
Broken Access Control vulnerability
<= 4.8.0
Dec 26, 2023
Broken Access Control vulnerability
<= 4.7.1
Oct 12, 2023
Reflected Cross Site Scripting (XSS) vulnerability
<= 4.7.0
Sep 5, 2023
Server Side Request Forgery (SSRF) vulnerability
<= 4.6.2
Jun 26, 2023
Unauthenticated Time-Based SQL Injection (SQLi) vulnerability
<= 3.4.1
Sep 13, 2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 3.2.8
Jul 26, 2021
Authenticated Blind SQL Injection (SQLi) vulnerability
<= 3.2.0
Jun 29, 2021