reputeinfosystems Vulnerabilities and Affected Products
Vulnerabilities associated with ARForms.
Products
Clear product- ARForms8 vulnerabilities
- ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup8 vulnerabilities
- Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress7 vulnerabilities
- ARPrice6 vulnerabilities
- bookingpress6 vulnerabilities
- arforms_form_builder5 vulnerabilities
- armember4 vulnerabilities
- Contact Form, Survey, Quiz & Popup Form Builder – ARForms3 vulnerabilities
- Social Share And Social Locker2 vulnerabilities
- appointment_booking_calendar_plugin_and_scheduling_plugin_bookingpress1 vulnerability
- ARForms Form Builder1 vulnerability
- ARMember Premium plugin for WordPress1 vulnerability
- pricing_table1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-54217MEDIUM | WordPress ARForms plugin <= 6.4.1 - Subscriber+ Plugin Settings Change vulnerabilityMissing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.1. CWE-862Dec 9, 2024 | CVSS5.4v3.1 | EPSS0.433% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-54216HIGH | WordPress ARForms plugin < 7.0.2 - Path Traversal vulnerabilityPath Traversal: '.../...//' vulnerability in reputeinfosystems ARForms allows Path Traversal. This issue affects ARForms: from n/a before 7.0.2. CWE-35Dec 6, 2024 | CVSS7.7v3.1 | EPSS0.539% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32703HIGH | WordPress ARForms plugin <= 6.4 - Subscriber+ Arbitrary File Deletion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4. | CVSS7.7v3.1 | EPSS0.577% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32704HIGH | WordPress ARForms plugin <= 6.4 - Subscriber+ Arbitrary WordPress Options Removal vulnerabilityMissing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4. CWE-862Jun 9, 2024 | CVSS7.1v3.1 | EPSS0.335% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32705HIGH | WordPress ARForms plugin <= 6.4 - Subscriber+ Arbitrary Plugin Activation/Deactivation VulnerabilityMissing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4. CWE-862Jun 9, 2024 | CVSS7.1v3.1 | EPSS0.382% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32702HIGH | WordPress ARForms plugin <= 6.4 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4. CWE-79Apr 24, 2024 | CVSS7.1v3.1 | EPSS0.357% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32706HIGH | WordPress ARForms plugin <= 6.4 - Subscriber+ SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4. CWE-89Apr 24, 2024 | CVSS8.5v3.1 | EPSS0.565% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-0969MEDIUM | ARMember <= 4.0.24 - Improper Access Control to Sensitive Information Exposure via REST APIThe ARMember plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's "Default Restriction" feature and view restricted post content. CWE-284Feb 5, 2024 | CVSS5.3v3.1 | EPSS0.482% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |