CVE-2021-47941

Severity CVSS v4.0:
HIGH
Type:
CWE-89 SQL Injection
Publication date:
10/05/2026
Last modified:
10/05/2026

Description

WordPress Plugin Survey & Poll 1.5.7.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wp_sap cookie parameter. Attackers can craft SQL payloads in the cookie to extract sensitive database information including usernames, passwords, and other confidential data from the WordPress database.