{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/repute-infosystems/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2024-13784"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ARForms"],"_cs_severities":["high"],"_cs_tags":["wordpress","plugin-vulnerability","php","deserialization"],"_cs_type":"advisory","_cs_vendors":["Repute InfoSystems"],"content_html":"\u003cp\u003eThe ARForms plugin (Contact Form, Survey, Quiz \u0026amp; Popup Form Builder) for WordPress contains a PHP Object Injection vulnerability in versions up to and including 1.8.5. The flaw originates from the insecure deserialization of untrusted input provided by users during form submissions. While the ARForms plugin itself does not include a POP chain, the vulnerability relies on the presence of a POP chain within other installed themes or plugins on the WordPress instance. If an attacker can leverage such a chain, they may perform unauthorized operations such as arbitrary file deletion, data exfiltration, or remote code execution. Because this vulnerability allows unauthenticated access to the deserialization process, it poses a high risk to WordPress environments that include common vulnerable plugins or complex themes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation depends on the availability of a POP chain within the target's environment. If triggered, impact includes complete site compromise through remote code execution, loss of sensitive database or configuration data, or service disruption via arbitrary file deletion. The vulnerability affects all users running ARForms 1.8.5 or older.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the ARForms plugin to the latest version immediately to remediate the insecure deserialization flaw.\u003c/li\u003e\n\u003cli\u003eAudit installed plugins and themes to identify and remove software that contains known POP chain gadgets.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests containing serialized PHP objects directed at endpoints associated with ARForms.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T10:24:37Z","date_published":"2026-08-16T10:24:37Z","id":"https://feed.craftedsignal.io/briefs/2026-08-arforms-php-injection/","summary":"The ARForms WordPress plugin (up to v1.8.5) is vulnerable to unauthenticated PHP Object Injection, which may lead to remote code execution when combined with a POP chain in other installed software.","title":"PHP Object Injection in ARForms Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-arforms-php-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Repute InfoSystems","version":"https://jsonfeed.org/version/1.1"}