CVE-2026-85682

CVE-2026-85682 published: The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrigin. This makes it po...

View full NVD advisory → ← Back to CVE watch