CVE-2024-13784Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-08-17)
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
01234Mentions · 2026-08-16: 3Mentions · 2026-08-17: 4PoC Mentioned / Linked · 2026-08-17: 1Technical Details · 2026-08-16: 3Technical Details · 2026-08-17: 108-1608-17
Signal classification3 categories
Disclosure
342.9%
General
342.9%
PoC
114.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-08-163
Disclosure2General1
2026-08-174
Disclosure1General2PoC1
Full discourse7 posts
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2024-13784 [HIGH PRIORITY] #Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthen... 🔗 https://exploitgrid.net/cve/CVE-2024-13784

    Post summary

    The post flags CVE‑2024‑13784 as a high‑priority issue for ARForms and includes a link to ExploitGrid, indicating a PoC exists, but lacks details on exploitation methods, active attacks, or patches.

    1000018
    33 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2026-19977 CVE-2024-13784 CVE-2026-15623 CVE-2026-19959 CVE-2026-19961 ..🧵👇

    Post summary

    The tweet only enumerates several CVE identifiers without offering any additional context, proof of concept, or actionable details.

    1000032
    33 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en complementos de WordPress ❗ CVE-2026-18316 ❗ CVE-2024-13784 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-plugins-de-wordpress/ https://t.co/WUVwgteMKE

    Post summary

    The post announces two new WordPress plugin vulnerabilities (CVE‑2024‑13784 and CVE‑2026‑18316) and directs readers to a CERT page for further information.

    01000183
    6.7K followersView on X
  • techs_targe@techs44576
    General

    エージェント収集レポート Daily Report 2026.8.17 ■セキュリティ・AI Safety関連 AI Safety 側は新規採用なしで、今日は WordPress とアーカイブ処理の確認が中心です。 ProSolution WP Client CVE-2026-16098 は未認証で任意ファイルをアップロードできる。公開ジョブポータルがあれば更新確認を先に。 https://nvd.nist.gov/vuln/detail/CVE-2026-16098 Pandora CVE-2026-74764 は TAR 展開で抽出先外へファイルを書ける。外部アーカイブの取込経路があれば更新確認を進めたい。 https://nvd.nist.gov/vuln/detail/CVE-2026-74764 ARForms CVE-2024-13784 は 1.8.5 以下の PHP Object Injection。別 plugin / theme の POP chain 併存有無まで確認したい。 https://nvd.nist.gov/vuln/detail/CVE-2024-13784 ■claude code update 由来 上流は静かで、前回の変更を運用へ当てる確認に向いています。 Claude Code の公開差分はなし。最新公開版は v2.1.233 のままです。 https://github.com/anthropics/claude-code/releases/tag/v2.1.233 ■xTECH 由来 今日の本レポートでは、実装人材、悪意なき暴走、信頼性重視 AI が並んでいます。 IT 大手4社が脱・人月へ FDE を拡充。日立は26年度内に国内 FDE 1000人を目指します。 https://xtech.nikkei.com/atcl/nxt/column/18/00001/11956/ OpenAI と Anthropic の評価で実システムへの未承認アクセス事案。自律動作の境界確認が要ります。 https://xtech.nikkei.com/atcl/nxt/column/18/00682/080600214/ KDDI が Buffmee 開始。書籍・雑誌・Webメディアなど約150コンテンツを情報源にしています。 https://xtech.nikkei.com/atcl/nxt/column/18/00086/00416/ オプトの業務改革に生成 AI を投入。「BPR と呼ばない」が成功条件として挙げられています。 https://xtech.nikkei.com/atcl/nxt/column/18/03076/080300029/

    Post summary

    The report lists several WordPress plugin CVEs with technical details but does not mention PoCs, exploit code, active exploitation, patches, or debunking claims.

    00001198
    531 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2024-13784 The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 v… https://www.cve.org/CVERecord?id=CVE-2024-13784

    Post summary

    CVE-2024-13784 identifies that the ARForms WordPress plugin (versions up to 1.8.5) is vulnerable to PHP Object Injection.

    000101.2K
    58.0K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    High-severity CVE-2024-13784 (CVSS 9.8) impacts ARForms WordPress plugin up to v1.8.5. SMBs should verify and update installations. https://nvd.nist.gov/vuln/detail/CVE-2024-13784 https://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/tgnjMPS8jm

    Post summary

    High‑severity CVE‑2024‑13784 (CVSS 9.8) impacts the ARForms WordPress plugin up to version 1.8.5, urging SMBs to verify and update installations.

    0000052
    93 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2024-13784 PHP Object Injection in ARForms Plugin for WordPress via Deserialization https://vulmon.com/vulnerabilitydetails?qid=CVE-2024-13784

    Post summary

    The text simply announces CVE-2024-13784 as a PHP Object Injection vulnerability in the ARForms WordPress plugin and provides a link to a vulnerability database but supplies no PoC, exploitation details, or mitigations.

    00000113
    4.1K followersView on X

Explore more