Extension WordPress
Vulnérabilités Contact Form, Survey, Quiz & Popup Form Builder – ARForms
Cette page rassemble les failles publiées pour Contact Form, Survey, Quiz & Popup Form Builder – ARForms, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Contact Form, Survey, Quiz & Popup Form Builder – ARForms
10 fiches
Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.7.4 – Unauthenticated Blind Arbitrary Shortcode Execution
The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.4. This is due to the software allowing users to…
*-1.7.4
1.7.5
20/03/2026
Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.7.0 – Unauthenticated Stored Cross-Site Scripting
The Contact Form, Survey, Quiz & Popup Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.7.0
1.7.1
06/01/2025
ARForms Form Builder <= 1.7.1 – HTML Injection
The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.7.1. This is due to the plugin not properly sanitizing and escaping…
*-1.7.1
1.7.2
05/12/2024
ARForms Form Builder <= 1.6.7 – Reflected Cross-Site Scripting
The ARForms Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-1.6.7
1.6.8
09/07/2024
ARForms Form Builder <= 1.6.4 – Missing Authorization to Authenticated(Subscriber+) Arbitrary Option Deletion
The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'arflite_remove_preview_data' function in all versions up…
*-1.6.4
1.6.5
25/04/2024
ARForms Form Builder <= 1.6.1 – Missing Authorization
The ARForms Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.6.1. This makes it possible for authenticated attackers, with subscriber-level access…
*-1.6.1
1.6.2
05/04/2024
ARForms Form Builder <= 1.6.1 – Cross-Site Request Forgery
The ARForms Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated…
*-1.6.1
1.6.2
05/04/2024
ARForms <= 1.5.8 – Unauthenticated Stored Cross-Site Scripting via arf_http_referrer_url
The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ arf_http_referrer_url’ parameter in all versions up to, and including, 1.5.8 due to…
*-1.5.8
1.5.9
03/01/2024
ARForms Form Builder <= 1.5.6 – Unauthenticated Cross-Site Scripting
The ARForms Form Builder plugin for WordPress is vulnerable to Cross-Site Scripting via an unspecified parameter in versions up to, and including, 1.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-1.5.6
1.5.7
23/11/2022
Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder < 1.5 – Cross-Site Scripting
The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
[*, 1.5)
1.5
02/11/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.