Record summary

CVE-2024-4620 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 11, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

ARForms - Premium WordPress Form Builder Plugin for WordPress

Browse ARForms / ARForms - Premium WordPress Form Builder Plugin for WordPress
VulnCheckVersion data not supplied

ARForms - Premium WordPress Form Builder Plugin

Default status: unaffected

CVE ListBefore 6.6affected

Default status: unaffected

CVE ListBefore 6.6affected

Nuclei templates

1
ProjectDiscoveryCRITICALArForms < 6.6 - Remote Code ExecutionCVSS 9.8

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form

Impact

Unauthenticated attackers can upload malicious PHP files to achieve remote code execution on WordPress servers running ARForms.

Remediation

Update ARForms plugin to version 6.6 or later.

Authorsiamnoooob, pdresearch
Template tagscvecve2024wordpresswpwp-pluginarformsintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:reputeinfosystems:arforms:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2