CVE-2024-13784 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 16:07pm

A security vulnerability tracked as CVE-2024-13784 has been identified in the ARForms plugin for WordPress, a tool used to build contact forms, surveys, quizzes, and popups. The flaw affects all versions of the plugin up to 1.8.5, and allows unauthenticated attackers to inject harmful code into your site by sending specially crafted form submissions.

This issue will not cause any actual harm on its own, as there is no related weakness built into the ARForms plugin itself. It only poses a risk if you have another WordPress plugin or theme installed that contains a specific related vulnerability. If that additional vulnerable component is present, an attacker could potentially use this flaw to delete files on your site, access sensitive private data, or run unauthorized code, depending on the specific weakness in the other plugin or theme.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784

« Back