CVE-2024-31270: WordPress ARForms Form Builder plugin <= 1.6.1 - Broken Access Control vulnerability
Published May 8, 2024
·Updated
Missing Authorization vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.
Affected Software
3 affected components
Repute InfoSystems ARForms Form Builder<=1.6.1
WordPress ARForms Form Builder<=1.6.1
reputeinfosystems Arforms Form Builder Wordpress<1.6.2
Remediation
Information
Update to 1.6.2 or a higher version.
Event History
May 8, 2024
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31270?
CVE-2024-31270 is considered a critical vulnerability due to its missing authorization, which could allow unauthorized access.
2
How do I fix CVE-2024-31270?
To fix CVE-2024-31270, update the ARForms Form Builder plugin to a version beyond 1.6.1.
3
Which versions are affected by CVE-2024-31270?
CVE-2024-31270 affects all versions of ARForms Form Builder up to and including version 1.6.1.
4
What impact does CVE-2024-31270 have on my website?
CVE-2024-31270 could potentially allow an attacker to access and manipulate form submissions without proper authorization.
5
Is CVE-2024-31270 specific to any platform?
CVE-2024-31270 is specifically associated with the Repute InfoSystems ARForms Form Builder plugin used on WordPress.