
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-13784 is a PHP Object Injection vulnerability in the Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress, affecting all versions up to and including 1.8.5. The flaw arises from deserialization of untrusted input submitted via forms, allowing unauthenticated attackers to inject arbitrary PHP objects. It was published on August 16, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data). The ARForms plugin deserializes user-supplied data from form submissions without adequate validation, enabling unauthenticated attackers to inject malicious PHP objects over the network with no user interaction required. Exploitation to achieve meaningful impact depends on the presence of a compatible Property-Oriented Programming (POP) chain in another installed plugin or theme — no POP chain is present in ARForms itself. If a POP chain exists in the environment, it can be leveraged to delete files, exfiltrate sensitive data, or execute arbitrary code (GitHub Advisory, Feedly).
If a compatible POP chain is present via another installed plugin or theme, an unauthenticated remote attacker could achieve full compromise of the WordPress site — including arbitrary code execution, deletion of arbitrary files, and retrieval of sensitive data such as credentials or database contents. Without a POP chain, the vulnerability has no direct impact. The attack is automatable and requires no privileges or user interaction, making it a high-risk exposure in environments with multiple plugins installed (GitHub Advisory, Feedly).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.519%, placing it in the 42nd percentile for exploitation likelihood within 30 days (GitHub Advisory). NVD SSVC assessment notes the attack is automatable with total technical impact potential, but exploitation is currently rated as "none" (Feedly).
O: or a: patterns in form fields).bash, curl, wget) following form submission activity.Update the ARForms plugin to a version newer than 1.8.5 as soon as a patched release becomes available from the vendor (GitHub Advisory). In the interim, audit all installed plugins and themes for known PHP gadget chains and remove any that are unnecessary or known to contain POP chains, as this eliminates the precondition for meaningful exploitation. Implement a Web Application Firewall (WAF) with rules to detect and block serialized PHP object payloads in form submissions. Monitor form submission logs for anomalous or oversized payloads (Feedly).
Wordfence included CVE-2024-13784 in their weekly WordPress vulnerability report covering August 10–16, 2026, highlighting it as a critical-severity finding (Wordfence Blog). The vulnerability was also discussed in a Reddit community brief on r/pwnhub as part of a daily CVE digest. No significant independent researcher commentary or vendor statements beyond standard advisory publication have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."