Arbitrary Shortcode Execution Vulnerability in ARForms Plugin for WordPress
CVE-2024-13785
5.6MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 March 2026
What is CVE-2024-13785?
The ARForms plugin for WordPress is susceptible to arbitrary shortcode execution due to inadequate validation before processing user-supplied values. This flaw allows unauthenticated attackers to execute malicious shortcodes, potentially leading to unauthorized actions and data compromise. All versions of the plugin up to and including 1.7.2 are affected, emphasizing the importance of timely updates and security practices for users relying on this tool for form management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Contact Form, Survey, Quiz & Popup Form Builder – ARForms * <= 1.7.2