Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ahmed Mohamed Almorabea

#35987of 53,633
7.5Total CVSS
Vulnerabilities · 1
PT-2019-14854
7.5
2019-09-27
WordPress · Arforms · CVE-2019-16902
**Name of the Vulnerable Software and Affected Versions** ARforms plugin version 3.7.1 for WordPress **Description** The issue allows unauthenticated deletion of an arbitrary file by supplying the full pathname through the `arf delete file` function in `arformcontroller.php`. **Recommendations** For ARforms plugin version 3.7.1, consider disabling the `arf delete file` function in `arformcontroller.php` to prevent unauthenticated file deletion until a patch is available.