Description
WordPress Plugin WordPress Poll is prone to multiple SQL injection and security bypass vulnerabilities. Exploiting these issues could allow an attacker to bypass certain security restrictions and perform unauthorized actions, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin WordPress Poll version 34.04 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 35.0 or latest
References
http://www.girlinthemiddle.net/2013/01/multiple-sql-injection-vulnerabilities.html
http://packetstormsecurity.com/files/119736/Cardoza-WordPress-Poll-34.05-SQL-Injection.html
http://seclists.org/bugtraq/2013/Jan/86