PT-2026-26796 · Repute Infosystems · Contact Form

Krzysztof Zając

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2024-13785

CVSS v3.1

5.6

Medium

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-13785

Affected Products

Contact Form