CVE-2024-4620
ArForms < 6.6 - Unauthenticated RCE
Record summary
CVE-2024-4620 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 7, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 11, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
ARForms - Premium WordPress Form Builder Plugin for WordPressBrowse ARForms / ARForms - Premium WordPress Form Builder Plugin for WordPress | VulnCheck | Version data not supplied | |
ARForms - Premium WordPress Form Builder PluginDefault status: unaffected | CVE List | Before 6.6 | affected |
arforms_form_builderBrowse reputeinfosystems / arforms_form_builderDefault status: unaffected | CVE List | Before 6.6 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALArForms < 6.6 - Remote Code ExecutionCVSS 9.8
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form
Impact
Unauthenticated attackers can upload malicious PHP files to achieve remote code execution on WordPress servers running ARForms.
Remediation
Update ARForms plugin to version 6.6 or later.
Source: ProjectDiscovery