CVE-2024-13784 (matched: php)

  • Sunday, 16th August, 2026
  • 10:09am

A security flaw has been identified in the ARForms WordPress plugin, a tool used to build contact forms, surveys, quizzes, and popup forms. All versions of this plugin up to and including version 1.8.5 are affected by this issue.

The vulnerability allows unauthenticated attackers (people who do not need admin login access to your site) to send malicious input through form submissions to inject harmful code objects into your site. It is important to note that this flaw only causes actual harm if you have another specific WordPress plugin or theme installed on your site that works with this type of attack. If you do not have that extra plugin or theme, this vulnerability does not pose a risk to your site.

If you do have a compatible additional plugin or theme installed, attackers could exploit this flaw to delete files on your site, access sensitive data stored on your site, or run unauthorized code, depending on the specifics of the extra plugin or theme present.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784

« Back