CVE-2019-16902: Path Traversal
Published Sep 27, 2019
·Updated
In the ARforms plugin 3.7.1 for WordPress, arfdeletefile in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.
Affected Software
1 affected component
reputeinfosystems Arforms Wordpress=3.7.1
Event History
Sep 27, 2019
CVE Published
via MITRE·10:56 AM
Data Sourced
via MITRE·10:56 AM
Description
Frequently Asked Questions
1
What is CVE-2019-16902?
CVE-2019-16902 is a vulnerability in the ARforms plugin 3.7.1 for WordPress that allows unauthenticated deletion of an arbitrary file.
2
How severe is CVE-2019-16902?
CVE-2019-16902 has a severity rating of 7.5 (high).
3
How does CVE-2019-16902 affect the ARforms plugin?
CVE-2019-16902 affects the ARforms plugin version 3.7.1 for WordPress.
4
How can I fix CVE-2019-16902?
To fix CVE-2019-16902, update the ARforms plugin to a version that addresses the vulnerability.
5
Where can I find more information about CVE-2019-16902?
More information about CVE-2019-16902 can be found in the provided references: http://almorabea.net/cve-2019-16902.txt and https://www.arformsplugin.com/documentation/changelog/