CVE-2024-4620

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form
Configurations

Configuration 1 (hide)

cpe:2.3:a:reputeinfosystems:arforms:*:*:*:*:*:wordpress:*:*

History

01 May 2025, 19:47

Type Values Removed Values Added
CPE cpe:2.3:a:reputeinfosystems:arforms:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/dc34dc2d-d5a1-4e28-8507-33f659ead647/ - () https://wpscan.com/vulnerability/dc34dc2d-d5a1-4e28-8507-33f659ead647/ - Exploit, Third Party Advisory
First Time Reputeinfosystems
Reputeinfosystems arforms
CWE NVD-CWE-noinfo

21 Nov 2024, 09:43

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/dc34dc2d-d5a1-4e28-8507-33f659ead647/ - () https://wpscan.com/vulnerability/dc34dc2d-d5a1-4e28-8507-33f659ead647/ -

12 Jul 2024, 16:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

07 Jun 2024, 14:56

Type Values Removed Values Added
Summary
  • (es) El complemento ARForms - Premium WordPress Form Builder para WordPress anterior a 6.6 permite a los usuarios no autenticados modificar los archivos cargados de tal manera que el código PHP se pueda cargar cuando se incluye una entrada de archivo de carga en un formulario.

07 Jun 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-07 06:15

Updated : 2025-05-01 19:47


NVD link : CVE-2024-4620

Mitre link : CVE-2024-4620

CVE.ORG link : CVE-2024-4620


JSON object : View

Products Affected

reputeinfosystems

  • arforms