A security vulnerability tracked as CVE-2024-13784 has been found in the ARForms plugin for WordPress, a popular tool used to build contact forms, surveys, quizzes and popups on WordPress sites. The flaw lets people who do not have login access to your website (unauthenticated attackers) inject malicious code into the plugin by submitting specially crafted form entries. All versions of the plugin up to and including version 1.8.5 are impacted.
This issue on its own cannot be used to harm your site, as the ARForms plugin does not include the extra components needed to turn the injected code into a damaging action. However, if you have another plugin or theme installed on your WordPress site that has a specific related weakness, an attacker could use this vulnerability to perform harmful actions. Depending on the weakness present in the other plugin or theme, these actions could include deleting files from your site, accessing sensitive data stored on your site, or running unauthorized code on your site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784