📦 Arforms

by Reputeinfosystems

🔍 What is Arforms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-4620

CRITICAL CVSS 9.8 Jun 7, 2024

This vulnerability in the ARForms WordPress plugin allows unauthenticated attackers to upload malicious PHP files through form submissions. Any WordPress site using ARForms plugin versions before 6.6 ...

CVE-2024-32703

HIGH CVSS 7.7 Jun 9, 2024

This CVE describes a Missing Authorization vulnerability in the ARForms WordPress plugin that allows subscribers (low-privileged users) to delete arbitrary files on the server. The vulnerability affec...

CVE-2024-32705

HIGH CVSS 7.1 Jun 9, 2024

This CVE describes a Missing Authorization vulnerability in the ARForms WordPress plugin that allows authenticated subscribers to arbitrarily activate or deactivate other plugins. This affects all Wor...

CVE-2024-32702

HIGH CVSS 7.1 Apr 24, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the ARForms WordPress plugin. When users visit a specially crafted link, the script executes in their browse...

CVE-2024-32706

HIGH CVSS 8.5 Apr 24, 2024

This SQL injection vulnerability in the ARForms WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affects all ARForms plugin versions up to 6.4, potentially compr...

CVE-2024-54217

MEDIUM CVSS 5.4 Dec 9, 2024

This CVE describes a Missing Authorization vulnerability in the ARForms WordPress plugin that allows authenticated users with subscriber-level permissions to modify plugin settings. This affects all A...