Arbitrary Shortcode Execution Vulnerability in ARForms Plugin for WordPress
CVE-2024-13785

5.6MEDIUM

What is CVE-2024-13785?

The ARForms plugin for WordPress is susceptible to arbitrary shortcode execution due to inadequate validation before processing user-supplied values. This flaw allows unauthenticated attackers to execute malicious shortcodes, potentially leading to unauthorized actions and data compromise. All versions of the plugin up to and including 1.7.2 are affected, emphasizing the importance of timely updates and security practices for users relying on this tool for form management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Contact Form, Survey, Quiz & Popup Form Builder – ARForms * <= 1.7.2

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Zając
.