CVE-2024-4620: ArForms < 6.6 - Unauthenticated RCE
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4620?
CVE-2024-4620 is considered a high severity vulnerability due to its ability to allow unauthenticated users to upload malicious PHP code.
How do I fix CVE-2024-4620?
To fix CVE-2024-4620, update the ARForms - Premium WordPress Form Builder Plugin to version 6.6 or later.
Who is affected by CVE-2024-4620?
Any website using ARForms - Premium WordPress Form Builder Plugin versions before 6.6 is affected by CVE-2024-4620.
What type of attack does CVE-2024-4620 enable?
CVE-2024-4620 enables an attack where unauthenticated users can modify uploaded files to execute arbitrary PHP code.
Is CVE-2024-4620 easily exploitable?
Yes, CVE-2024-4620 is easily exploitable because it does not require any authentication to upload malicious files.