A security flaw tracked as CVE-2024-13784 has been identified in the Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress. The flaw impacts all versions of the plugin up to and including version 1.8.5, and allows unauthenticated attackers (people who do not have login access to your website) to send specially crafted form submissions that can inject harmful code into your site's backend systems. This flaw cannot be exploited to cause damage on its own, as there is no built-in method for attackers to leverage it to harm your site. It only poses a risk if you have another WordPress plugin or theme installed on your site that has its own related security gap. If such a vulnerable third-party plugin or theme is present on your site, attackers could use this flaw to delete files, steal sensitive data like customer information or private site content, or even run unauthorized code on your site, with the exact level of risk depending on the specific gap in the other installed tool.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784