A security vulnerability has been discovered in the ARForms plugin, a popular WordPress tool for building contact forms, surveys, quizzes and popup forms. The flaw impacts all versions of the plugin up to and including version 1.8.5, and allows unauthenticated attackers (people who do not have login credentials for your website) to submit malicious input through forms on your site.
On its own, this vulnerability cannot be exploited to cause damage. It only poses a risk if you have another WordPress plugin or theme installed on your site that contains a related weakness. If that additional software is present, an attacker could use this flaw to delete files on your site, access sensitive data, or run unauthorized code, depending on the specific weakness in the other installed tool.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784