CVE-2024-13784
Received Received - Intake

PHP Object Injection in ARForms WordPress Plugin

Vulnerability report for CVE-2024-13784, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-16

Last updated on: 2026-08-16

Assigner: Wordfence

Description

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-16
Last Modified
2026-08-16
Generated
2026-08-16
AI Q&A
2026-08-16
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
arforms arforms to 1.8.5 (inc)
reputeinfosystems arforms to 1.8.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a PHP Object Injection flaw in the ARForms WordPress plugin versions up to 1.8.5. It allows unauthenticated attackers to inject a PHP object via deserialization of untrusted input from form submissions. The impact depends on other installed plugins or themes containing a POP chain, which could lead to actions like arbitrary file deletion, sensitive data retrieval, or code execution.

Detection Guidance

Detecting this vulnerability requires checking if the ARForms plugin version 1.8.5 or older is installed on your WordPress site. You can verify this by inspecting the plugin files or checking the WordPress admin panel under Plugins. No specific commands are provided in the context for detection.

Impact Analysis

If you use the vulnerable ARForms plugin, an attacker could exploit this to perform actions like deleting files, stealing data, or running malicious code on your site. However, this requires another plugin or theme with a POP chain to be present for full exploitation.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR or HIPAA if an attacker exploits it to retrieve sensitive data or execute unauthorized actions. Exploitation depends on the presence of a POP chain in another plugin or theme. If exploited, it may lead to unauthorized access to personal data, violating GDPR principles or HIPAA requirements for data protection.

Mitigation Strategies

Immediately update the ARForms plugin to the latest version if available. If the plugin is no longer maintained or updated, consider removing it entirely from your WordPress installation. Ensure no other plugins or themes with POP chains are installed, as they could be exploited in conjunction with this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-13784. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart