CVE-2024-54216 HIGH

CVE-2024-54216: WordPress ARForms plugin <= 6.4.1 - Subscriber+ Arbitrary File Read vulnerability

Vendor Reputeinfosystems
Product ARForms
Weakness CWE-35
Published December 6, 2024
Last update April 28, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms arforms allows Path Traversal.This issue affects ARForms: from n/a through <= 6.4.1.

Explanation of Vulnerability in Simple Terms

02Summary

ARForms versions 6.4.1 and earlier contain an information disclosure vulnerability. An attacker with low-level user privileges can read sensitive data from the application, potentially including confidential information stored in the system. The vulnerability requires network access and valid user credentials but no additional user interaction. Scope is changed, meaning the impact may extend beyond the vulnerable component itself.

What an attacker can do

03Attacker Capabilities

Read sensitive data and confidential information from the application.

Potential impact on your site

04Site Impact

Unauthorized users with basic accounts can access confidential data they should not see.

Conditions required to exploit

05Prerequisites

Valid user account with low-level privileges; network access to the application.

Key dates

06Disclosure timeline

December 6, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE