Junglewise Threat Intelligence

CVE-2026-57338: Repute InfoSystems ARForms unauthenticated XSS

CVE-2026-57338 · Severity: high · CVSS 7.1 · Published 2026-06-29

Technologies: Repute InfoSystems ARForms. Vendors: Repute InfoSystems.

Executive brief

ARForms is a popular form builder plugin for WordPress websites. A security vulnerability in versions 7.1.2 and earlier allows unauthenticated attackers to execute malicious scripts in the browsers of other users. This could lead to unauthorized actions being performed on behalf of site administrators, redirection to malicious websites, or the theft of sensitive session information.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the ARForms plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript into a victim's browser session. Exploitation requires a user to interact with a specially crafted link or page. Successful exploitation can result in the execution of malicious scripts in the context of the victim's browser, potentially leading to session hijacking or administrative account takeover if the victim is a site administrator. The issue is addressed in version 7.2.

Affected products

  • Repute InfoSystems ARForms <= 7.1.2

Timeline

  • 2026-04-24: other: Vulnerability reported by researcher dutafi
  • 2026-06-29: advisory: Advisory published by Patchstack and NVD
  • 2026-06-29: patched: Version 7.2 released to address the vulnerability

References

Related threats