CVE-2024-31272: WordPress ARForms Form Builder plugin <= 1.6.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 12, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.
Affected Software
3 affected components
Repute InfoSystems ARForms Form Builder<=1.6.1
WordPress ARForms Form Builder<=1.6.1
reputeinfosystems Arforms Form Builder Wordpress<1.6.2
Remediation
Information
Update to 1.6.2 or a higher version.
Event History
Apr 12, 2024
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31272?
CVE-2024-31272 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2024-31272?
To fix CVE-2024-31272, upgrade the Repute InfoSystems ARForms Form Builder to version 1.6.2 or later.
3
What software is affected by CVE-2024-31272?
CVE-2024-31272 affects Repute InfoSystems ARForms Form Builder versions up to and including 1.6.1.
4
What type of vulnerability is CVE-2024-31272?
CVE-2024-31272 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Is CVE-2024-31272 a WordPress vulnerability?
Yes, CVE-2024-31272 also affects the WordPress version of the ARForms Form Builder plugin.