Vendor
The ARForms WordPress plugin (up to v1.8.5) is vulnerable to unauthenticated PHP Object Injection, which may lead to remote code execution when combined with a POP chain in other installed software.