Severity: Critical (CVSS 9.8)
Affected Systems: Reputeinfosystems Contact Form, Survey, Quiz & Popup Form Builder – Arforms; Wordpress Wordpress
Overview
Contact Form, Survey, Quiz & Popup Form Builder – ARForms
A critical vulnerability identified as CVE-2024-13784 has been disclosed.
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Risk
CVSS and CISA data indicate the following:
- Review the OpenCVE and vendor advisory for exploit conditions and impact
OpenCVE Analysis
CVSS v4.0 N/ACVSS v3.1 9.8 CriticalCVSS v3.0 N/ACVSS v2 N/AKEV noEPSS yesSSVC no
- OpenCVE title: Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection
- Severity score: Critical (CVSS 9.8)
- EPSS score: 0.00519
- Weaknesses: CWE-502
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
Required Action
Review the OpenCVE detail page and linked vendor advisory, then apply the vendor-provided update or mitigation for the affected product.
Prioritize systems where the affected product is internet-facing, handles authentication, or runs with elevated privileges.
Verify Updates
Confirm whether your environment uses the affected product(s): Reputeinfosystems Contact Form, Survey, Quiz & Popup Form Builder – Arforms; Wordpress Wordpress.
After remediation, verify the installed version against the fixed or unaffected versions listed by the vendor.
Temporary Mitigation (if patch is not available)
Use the mitigation published by the vendor. If no vendor mitigation is available, reduce exposure to the affected product, restrict access to trusted users or networks, and increase monitoring until an update can be applied.
Recommendation
- Use OpenCVE, vendor, and source references as the source of truth for affected versions and remediation
- Patch or mitigate affected products after confirming exposure in your environment
- Monitor affected systems for unusual activity until remediation is complete
Support
If you require assistance, please contact our support team.
Immediate action is strongly recommended to protect your infrastructure.
Source Details
Customer Responsibility and Backups
Before applying updates, mitigations, or configuration changes, customers should take and verify current backups or snapshots of affected systems.
Customers are responsible for managing their servers, validating their own backups, testing changes, and ensuring they can restore services if an update or mitigation causes an issue.
Sunday, August 16, 2026
