CVE-2024-13784 (matched: php)

  • Monday, 17th August, 2026
  • 10:09am

A security vulnerability has been found in the ARForms WordPress plugin, a tool used to build contact forms, surveys, quizzes, and popup forms. The flaw affects all versions of the plugin up to and including version 1.8.5, and allows unauthenticated users (people who are not logged into your site) to submit specially crafted form entries that inject harmful PHP objects into your site’s backend systems.

This vulnerability cannot be fully exploited to cause harm on its own, as there is no built-in vulnerable code in the ARForms plugin that lets attackers take further action. It only poses a real risk if you have another WordPress plugin or theme installed on your site that contains a related vulnerability. If such additional software is present, an attacker could potentially use this flaw to delete files on your site, access sensitive private data, or run unauthorized code, depending on the capabilities of the other vulnerable plugin or theme.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784

« Back