WordPress ARForms是WordPress基金会开源的一款构建表单与调查问卷的插件。 WordPress ARForms 1.8.5及之前版本存在反序列化注入漏洞,该漏洞源于对来自表单提交的不可信输入进行反序列化,可能导致未经身份验证的攻击者注入PHP对象,若存在POP链则可能删除任意文件、检索敏感数据或执行代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| reputeinfosystems | Contact Form, Survey, Quiz & Popup Form Builder – ARForms | ≤ 1.8.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| reputeinfosystems | Contact Form, Survey, Quiz & Popup Form Builder – ARForms | 0 ~ 1.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet