A security flaw has been found in the ARForms plugin for WordPress, a tool used to build contact forms, surveys, quizzes, and popup forms for websites. The vulnerability affects all versions of the plugin up to and including version 1.8.5, and is classified as a PHP Object Injection issue.
This flaw lets unauthenticated attackers (people who do not have login access to your website) send malicious input through form submissions created with the ARForms plugin. On its own, the vulnerable ARForms plugin does not have a built-in way for this flaw to be abused, so it will not cause problems for your site if you do not have other WordPress plugins or themes installed that contain a related security gap called a POP chain.
If you do have other plugins or themes on your WordPress site with that related POP chain gap, an attacker could use this ARForms flaw to delete files on your site, access private sensitive information, or run unauthorized code on your site. The exact risks depend on what the other vulnerable plugin or theme allows an attacker to do.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784