CVE-2024-13784 (matched: wordpress)

  • Monday, 17th August, 2026
  • 10:08am

A security flaw has been found in the ARForms plugin for WordPress, a tool used to build contact forms, surveys, quizzes, and popup forms. The flaw affects all versions of the plugin up to and including version 1.8.5. It lets unauthenticated attackers (people who do not need to log into your site's admin area) send specially crafted form submissions that inject malicious code objects into your website.

This specific vulnerability does not cause harm on its own. It only becomes a risk if you also have another WordPress plugin or theme installed on your site that has a related unpatched security weakness, called a POP chain. If that additional vulnerable software is present, an attacker could use the two flaws together to delete files on your site, steal sensitive data such as customer information or admin login credentials, or even take full control of your website to run unauthorized code, depending on what the other vulnerable software allows.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784

« Back