The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.4.1 does not properly escape user-controlled input when it is reflected in some of its AJAX actions.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 28 May 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Reputeinfosystems
Reputeinfosystems arforms
Weaknesses CWE-79
CPEs cpe:2.3:a:reputeinfosystems:arforms:*:*:*:*:*:wordpress:*:*
Vendors & Products Reputeinfosystems
Reputeinfosystems arforms

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-01T18:04:49.774Z

Reserved: 2024-01-11T14:11:34.929Z

Link: CVE-2024-0427

cve-icon Vulnrichment

Updated: 2024-08-01T18:04:49.774Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-12T06:15:08.903

Modified: 2025-05-28T20:05:04.743

Link: CVE-2024-0427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.