PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.066
EPSS Ranking 93.3%