Closed ghost closed 7 years ago
There is a current flaw in wp-polls that allows people to embed the following into a page: http://example.com/wp-admin/admin-ajax.php?action=polls&view=process&poll_id=POLLID&poll_POLLID=ANSWER&poll_POLLID_nonce=POLLNONCE
There is a current flaw in wp-polls that allows people to embed the following into a page: http://example.com/wp-admin/admin-ajax.php?action=polls&view=process&poll_id=POLLID&poll_POLLID=ANSWER&poll_POLLID_nonce=POLLNONCE