The Poll Maker WordPress plugin before 4.0.2 does not sanitise and escape some settings, which could allow high privilege users such as admin to perform Store Cross-Site Scripting attack even when unfiltered_html is disallowed
| Software | From | Fixed in |
|---|---|---|
| ays-pro / poll_maker | - | 4.0.2 |