CVE-2024-13784 (matched: php)

  • Monday, 17th August, 2026
  • 04:07am

A security flaw has been identified in the ARForms WordPress plugin, a popular tool for building contact forms, surveys, quizzes, and popup forms. The flaw impacts all versions of the plugin up to and including version 1.8.5, and relates to how the plugin handles data submitted through its forms. It makes it possible for attackers who do not have login access to your WordPress site to send malicious data through these forms.

On its own, this flaw cannot cause harm to your site. No related security gap (called a POP chain) is built into the ARForms plugin itself, so the flaw only poses a risk if you have another WordPress plugin or theme installed that has a matching related security gap. If such a plugin or theme is present, an attacker could exploit this flaw to perform harmful actions, including deleting files on your site, accessing sensitive data, or running unauthorized code, with the exact impact depending on what the other related security gap allows.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784

« Back