CVE-2024-10504: Reputeinfosystems Arforms
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
Affected products
- Reputeinfosystems Arforms: before 1.7.1 (fixed in 1.7.1)
Published 2025-05-15. Last modified 2026-06-17.