Title: PatchStack Reporting Cross Site Scripting (XSS)
Last modified: July 27, 2026

---

# PatchStack Reporting Cross Site Scripting (XSS)

 *  [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [1 week, 4 days ago](https://wordpress.org/support/topic/patchstack-reporting-cross-site-scripting-xss/)
 * Morning Lester,
 * Thanks for the great plugin.
 * Patchstack are currently reporting a Cross Site Scripting (XSS) for all version
   up-to-and-including 2.77.3:
 * [https://patchstack.com/database/wordpress/plugin/wp-polls/vulnerability/wordpress-wp-polls-plugin-2-77-3-cross-site-scripting-xss-vulnerability?_s_id=cve](https://patchstack.com/database/wordpress/plugin/wp-polls/vulnerability/wordpress-wp-polls-plugin-2-77-3-cross-site-scripting-xss-vulnerability?_s_id=cve)
 * Are you able to confirm if this is being dealt with and/is it being correctly
   reported? Let us know if we can do anything to assist (testing etc).
 * Many thanks,
 * The page I need help with: _[[log in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fpatchstack-reporting-cross-site-scripting-xss%2F%3Foutput_format%3Dmd&locale=en_US)
   to see the link]_

Viewing 3 replies - 1 through 3 (of 3 total)

 *  Plugin Author [Lester Chan](https://wordpress.org/support/users/gamerz/)
 * (@gamerz)
 * [1 week, 4 days ago](https://wordpress.org/support/topic/patchstack-reporting-cross-site-scripting-xss/#post-18976012)
 * Hmm, this was in 16 Oct, 2025, all the XSS reported to me so far has been fixed.
   I am not sure if patchstack reported version is correct.
   Anyway, I am using AI
   to rewrite the plugin to be more modern, maybe you can help test it [https://github.com/lesterchan/wp-polls/archive/refs/heads/master.zip](https://github.com/lesterchan/wp-polls/archive/refs/heads/master.zip)
 *  Thread Starter [stopps](https://wordpress.org/support/users/stopps/)
 * (@stopps)
 * [1 week, 1 day ago](https://wordpress.org/support/topic/patchstack-reporting-cross-site-scripting-xss/#post-18979846)
 * Hi Lester,
 * Thanks for the response, I’ll schedule some time to take a look at the new AI
   version and do some testing.
 * Just so you are aware, Wordfence are now also reporting the new issue: [https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-polls/wp-polls-2773-authenticated-administrator-stored-cross-site-scripting](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-polls/wp-polls-2773-authenticated-administrator-stored-cross-site-scripting)
 * They are classifying it as low risk as it is an Administrator+ exploit:
 * “The WP-Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting
   in versions up to, and including, 2.77.3 due to insufficient input sanitization
   and output escaping. This makes it possible for authenticated attackers, with
   administrator-level access and above, to inject arbitrary web scripts in pages
   that will execute whenever a user accesses an injected page. This only affects
   multi-site installations and installations where unfiltered_html has been disabled.”
 * I’m not sure how this can be classified as a vulnerability if someone has chosen
   to disabled unfiltered_html, but you’ll probably want to issue a patch just to
   avoid the plugin directory restricting the plugin’s access.
 * All the best,
 *  Plugin Author [Lester Chan](https://wordpress.org/support/users/gamerz/)
 * (@gamerz)
 * [1 week ago](https://wordpress.org/support/topic/patchstack-reporting-cross-site-scripting-xss/#post-18981141)
 * Rewrite is done and as to my best ability [https://wordpress.org/support/topic/wp-polls-3-0-0/](https://wordpress.org/support/topic/wp-polls-3-0-0/)

Viewing 3 replies - 1 through 3 (of 3 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fpatchstack-reporting-cross-site-scripting-xss%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/wp-polls/assets/icon.svg?rev=977996)
 * [WP-Polls](https://wordpress.org/plugins/wp-polls/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wp-polls/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wp-polls/)
 * [Active Topics](https://wordpress.org/support/plugin/wp-polls/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wp-polls/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wp-polls/reviews/)

 * 5 replies
 * 2 participants
 * Last reply from: [Lester Chan](https://wordpress.org/support/users/gamerz/)
 * Last activity: [1 week ago](https://wordpress.org/support/topic/patchstack-reporting-cross-site-scripting-xss/#post-18981141)
 * Status: not resolved