"value":"The Poll Maker \u2013 Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injection via the order_by parameter in all versions up to, and including, 5.4.6 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')",
"cweId":"CWE-89"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"ays-pro",
"product":{
"product_data":[
{
"product_name":"Poll Maker \u2013 Versus Polls, Anonymous Polls, Image Polls",