PHP Object Injection Risk in ARForms Plugin for WordPress
CVE-2024-13784

9.8CRITICAL

What is CVE-2024-13784?

The ARForms plugin for WordPress is susceptible to PHP Object Injection due to improper deserialization of untrusted input from user form submissions. This vulnerability exists across all versions up to and including 1.8.5. Although there is no current known object property (POP) chain within the affected software, the potential for exploitation arises when an additional plugin or theme containing a POP chain is present. In such scenarios, an unauthenticated attacker could potentially execute harmful actions including file deletion, sensitive data retrieval, or arbitrary code execution depending on the specific POP chain utilized.

Affected Version(s)

Contact Form, Survey, Quiz & Popup Form Builder – ARForms 0 <= 1.8.5

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Zając
.