Security Advisory

CVE-2019-16902

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-09-27 10:56:35
Last updated 2024-08-05 01:24:48
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.