CVE-2024-4620: Reputeinfosystems Arforms
Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form
Affected products
- Reputeinfosystems Arforms: before 6.6 (fixed in 6.6)
Published 2024-06-07. Last modified 2026-06-17.