CVE-2024-0427

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.4.1 does not properly escape user-controlled input when it is reflected in some of its AJAX actions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:reputeinfosystems:arforms:*:*:*:*:*:wordpress:*:*

History

28 May 2025, 20:05

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/1806fef3-d774-46e0-aa48-7a101495f4eb/ - () https://wpscan.com/vulnerability/1806fef3-d774-46e0-aa48-7a101495f4eb/ - Exploit, Third Party Advisory
First Time Reputeinfosystems
Reputeinfosystems arforms
CPE cpe:2.3:a:reputeinfosystems:arforms:*:*:*:*:*:wordpress:*:*
CWE CWE-79

21 Nov 2024, 08:46

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/1806fef3-d774-46e0-aa48-7a101495f4eb/ - () https://wpscan.com/vulnerability/1806fef3-d774-46e0-aa48-7a101495f4eb/ -

03 Jul 2024, 01:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

13 Jun 2024, 18:36

Type Values Removed Values Added
Summary
  • (es) El complemento ARForms - Premium WordPress Form Builder Plugin de WordPress anterior a 6.4.1 no escapa correctamente a la entrada controlada por el usuario cuando se refleja en algunas de sus acciones AJAX.

12 Jun 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-12 06:15

Updated : 2025-05-28 20:05


NVD link : CVE-2024-0427

Mitre link : CVE-2024-0427

CVE.ORG link : CVE-2024-0427


JSON object : View

Products Affected

reputeinfosystems

  • arforms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')