A popular WordPress plugin called ARForms, used to build contact forms, surveys, quizzes, and popups, has a security flaw in all versions up to and including 1.8.5. The issue lets anyone—even people without login access to your website—send specially crafted submissions through your ARForms forms that could inject harmful code into your site’s backend systems.
This flaw on its own does not cause damage, because the ARForms plugin does not have the built-in ability to turn that injected code into a harmful action. It only becomes a risk if you have another WordPress plugin or theme installed on your site that has a separate related weakness.
If you do have another vulnerable plugin or theme active on your site, an attacker could use this flaw to delete files from your site, steal private information stored on your site, or even run unauthorized commands on your hosting account, depending on the weakness in the other add-on.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2024-13784