ARforms

Explore ARforms vulnerabilities across all versions. Currently tracking 15 known vulnerabilities, including severity, impact, and patch status.

01234567891017.10.2018Today17.10.20187.5Repute ARForms <= 3.5.1 - Unauthenticated Arbitrary File Deletion via Path Traversal CVSS 7.5 · 17.10.201811.10.20197.5ARforms <= 3.7.1 - Unauthenticated Arbitrary File Deletion CVSS 7.5 · 11.10.201922.04.20248.1ARForms <= 6.4 - Missing Authorization to Arbitrary File Deletion CVSS 8.1 · 22.04.20244.3ARForms <= 6.4 - Missing Authorization to Arbitrary Option Deletion CVSS 4.3 · 22.04.20248.8ARforms <= 6.4 - Authenticated (Subscriber+) SQL Injection CVSS 8.8 · 22.04.20246.1ARforms <= 6.4 - Reflected Cross-Site Scripting CVSS 6.1 · 22.04.20244.3ARForms <= 6.4 - Missing Authorization to Arbitrary Plugin Activation/Deactivation CVSS 4.3 · 22.04.202417.05.202410.0ARForms Form Builder <= 6.5 - Unauthenticated Arbitrary File Upload CVSS 10.0 · 17.05.20244.4ARforms <= 6.5 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 17.05.202422.05.20246.1ARForms - Premium WordPress Form Builder <= 6.4.0 - Reflected Cross-Site Scripting CVSS 6.1 · 22.05.202402.12.20247.7ARForms <= 6.4.1 - Directory Traversal to Authenticated (Subscriber+) Arbitrary File Read CVSS 7.7 · 02.12.20245.4ARForms <= 6.4.1 - Missing Authorization to Plugin Settings Change CVSS 5.4 · 02.12.202423.06.20267.2ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Parameter CVSS 7.2 · 23.06.202629.06.20266.1ARforms <= 7.1.2 - Reflected Cross-Site Scripting CVSS 6.1 · 29.06.202622.07.20267.2ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values CVSS 7.2 · 22.07.2026

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage73%
Open

4

Fixed

11

Get automatic notifications for all ARforms vulnerabilities before they are exploited.

Vulnerability Records

15 records
Showing 1–10 of 15 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C