CVE-2024-13784 (matched: wordpress)

  • Monday, 17th August, 2026
  • 16:10pm

A security flaw has been identified in the ARForms plugin for WordPress, a tool used to build contact forms, surveys, quizzes, and popup forms. The flaw impacts all versions of the plugin up to and including version 1.8.5.

The issue allows unauthenticated attackers (people who do not have login access to your WordPress site) to send malicious data through form submissions on your site, which can inject harmful code into your site's backend systems.

This flaw on its own does not cause direct damage, as there is no built-in weakness in the ARForms plugin that lets attackers exploit the injected code. If you have another WordPress plugin or theme installed on your site that has a related security weakness, attackers could use this combined gap to delete files on your site, access sensitive information like customer data or admin credentials, or even run code on your site depending on the other vulnerable software.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784

« Back