
Poll, Poll Forms – WordPress Poll plugin by Poll Builder Security & Risk Analysis
wordpress.org/plugins/poll-builderPoll Builder plugin allows you easiest way to create Poll forms via the Poll plugin.
Is Poll, Poll Forms – WordPress Poll plugin by Poll Builder Safe to Use in 2026?
Use With Caution
Score 64/100Poll, Poll Forms – WordPress Poll plugin by Poll Builder has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "poll-builder" plugin v1.3.5 presents a mixed security posture. While it demonstrates good practices in SQL query sanitization (91% prepared statements) and avoids file operations and external HTTP requests, significant concerns arise from its attack surface and taint analysis.
The plugin exposes 5 entry points, with 2 AJAX handlers lacking authentication checks. This is a critical oversight, as it allows unauthorized users to potentially interact with sensitive plugin functionalities. The taint analysis reveals 7 flows with unsanitized paths, 4 of which are classified as high severity. This indicates a strong possibility of vulnerabilities like Cross-Site Scripting (XSS) or other injection attacks if user-supplied data is not properly validated and escaped before use.
The plugin's vulnerability history, despite being limited to one medium-severity CVE related to XSS, coupled with the high severity taint flows, suggests a pattern of input sanitization weaknesses. The fact that this CVE is currently unpatched is a serious red flag. While the plugin has strengths in its SQL practices and avoidance of certain risky operations, the combination of an unprotected attack surface and unpatched XSS vulnerabilities demands immediate attention.
Key Concerns
- Unpatched CVE
- High severity taint flows
- AJAX handlers without auth checks
- Unescaped output (40% of outputs)
- Flows with unsanitized paths
- Limited nonce checks
- Limited capability checks
Poll, Poll Forms – WordPress Poll plugin by Poll Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Poll Builder <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Poll, Poll Forms – WordPress Poll plugin by Poll Builder Release Timeline
Poll, Poll Forms – WordPress Poll plugin by Poll Builder Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Poll, Poll Forms – WordPress Poll plugin by Poll Builder Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Poll, Poll Forms – WordPress Poll plugin by Poll Builder Maintenance & Trust
Maintenance Signals
Community Trust
Poll, Poll Forms – WordPress Poll plugin by Poll Builder Alternatives
Knowledge Base – Knowledge Base Maker
knowledge-base-maker
Organize your documentation and FAQs with our Knowledge Base Maker plugin. It's easy to use, flexible and professional.
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
Crowdsignal Dashboard – Polls, Surveys & more
polldaddy
Manage your Crowdsignal polls, surveys, quizzes, and ratings directly from the WordPress dashboard.
WP-Polls
wp-polls
Adds an AJAX poll system to your WordPress blog. You can also easily add a poll into your WordPress's blog post/page.
YOP Poll
yop-poll
Use a full option polling solution to get the answers you need. YOP Poll is the perfect, easy to use poll plugin for your WordPress site.
Poll, Poll Forms – WordPress Poll plugin by Poll Builder Developer Profile
6 plugins · 2K total installs
How We Detect Poll, Poll Forms – WordPress Poll plugin by Poll Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/poll-builder/com/assets/js/WpYplBlockMin.js/wp-content/plugins/poll-builder/com/assets/js/YplAdmin.js/wp-content/plugins/poll-builder/com/assets/js/select2.js/wp-content/plugins/poll-builder/com/assets/js/YplClassic.js/wp-content/plugins/poll-builder/com/assets/js/WpYplBlockMin.js/wp-content/plugins/poll-builder/com/assets/js/YplAdmin.js/wp-content/plugins/poll-builder/com/assets/js/select2.js/wp-content/plugins/poll-builder/com/assets/js/YplClassic.jspoll-builder/com/assets/js/YplClassic.js?ver=HTML / DOM Fingerprints
ypl-answerpoll-content-wrapper-ypl-gutenberg-logodata-ypl-idYPL_GUTENBERG_PARAMSYPL_ADMIN_DATAYPL_DATA<p>ypl-classic-question</p>