CVE-2024-54217: WordPress ARForms plugin <= 6.4.1 - Subscriber+ Plugin Settings Change vulnerability
Published Dec 9, 2024
·Updated
Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <= 6.4.1.
Affected Software
3 affected components
Repute info systems ARForms>n/a, <=6.4.1
WordPress ARForms<=6.4.1
reputeinfosystems Arforms Wordpress<=6.4.1
Event History
Dec 9, 2024
CVE Published
via MITRE·12:58 PM
Data Sourced
via MITRE·12:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-54217?
CVE-2024-54217 is classified as a Missing Authorization vulnerability.
2
How do I fix CVE-2024-54217?
To mitigate CVE-2024-54217, update Repute Info Systems ARForms to version 6.4.2 or later.
3
What versions of ARForms are affected by CVE-2024-54217?
CVE-2024-54217 affects all versions of ARForms from n/a up to and including 6.4.1.
4
Who is impacted by CVE-2024-54217?
Users of Repute Info Systems ARForms versions 6.4.1 and earlier are impacted by CVE-2024-54217.
5
Is CVE-2024-54217 exploitable remotely?
Yes, CVE-2024-54217 can potentially be exploited remotely due to the nature of the Missing Authorization vulnerability.