PHP Object Injection Risk in ARForms Plugin for WordPress
CVE-2024-13784
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 August 2026
What is CVE-2024-13784?
The ARForms plugin for WordPress is susceptible to PHP Object Injection due to improper deserialization of untrusted input from user form submissions. This vulnerability exists across all versions up to and including 1.8.5. Although there is no current known object property (POP) chain within the affected software, the potential for exploitation arises when an additional plugin or theme containing a POP chain is present. In such scenarios, an unauthenticated attacker could potentially execute harmful actions including file deletion, sensitive data retrieval, or arbitrary code execution depending on the specific POP chain utilized.
Affected Version(s)
Contact Form, Survey, Quiz & Popup Form Builder – ARForms 0 <= 1.8.5