Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2024-13784: ARForms Plugin <= 1.8.5: Unauthenticated Attackers Can Delete Files
CVE-2024-13784 · published 19 days ago
Summary
The ARForms plugin for WordPress has a security issue that allows unauthenticated attackers to delete files or access sensitive data if another plugin or theme is installed that contains a specific type of vulnerability. This issue affects all versions up to 1.8.5. To protect your site, update the ARForms plugin to a version higher than 1.8.5.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| reputeinfosystems | contact form, survey, quiz & popup form builder – arforms | <= 1.8.5 |
Original advisory text
Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published16 Aug 2026
Updated3 Sep 2026
First seen16 Aug 2026
Monitor software like this
Free during beta