Beta

Report

ARForms <= 6.4 is vulnerable to Subscriber+ Arbitrary WordPress Options Removal vulnerability

Subscriber
Published
2024-04-21

The ARforms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on a function in all versions up to, and including, 6.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary options.

CVSS

Score:7.1

Severity:High

Version: 6.4

There is a patch available in v6.4.1 and we strongly recommend you update to this version as soon as possible.