CVE-2024-1945

HIGH

ARForms Form Builder <1.6.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'arflite_remove_preview_data' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber access and above, to delete arbitrary site options, resulting in loss of availability.

Scores

CVSS v3 7.1
EPSS 0.0043
EPSS Percentile 34.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
reputeinfosystems/Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder < 1.6.4
reputeinfosystems/Contact Form, Survey, Quiz & Popup Form Builder – ARForms < 1.6.4
Published May 02, 2024
Tracked Since Feb 18, 2026