CVE Published: 07/06/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: WPScan |
Vendor: Unknown |
Product: ARForms - Premium WordPress Form Builder Plugin Status : PUBLISHED
CVE-2024-4620 Description
The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form