The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 01 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Reputeinfosystems
Reputeinfosystems arforms |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:reputeinfosystems:arforms:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Reputeinfosystems
Reputeinfosystems arforms |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T20:47:41.237Z
Reserved: 2024-05-07T19:27:04.896Z
Link: CVE-2024-4620
Updated: 2024-08-01T20:47:41.237Z
Status : Analyzed
Published: 2024-06-07T06:15:11.763
Modified: 2025-05-01T19:47:03.910
Link: CVE-2024-4620
No data.
OpenCVE Enrichment
No data.
Weaknesses