High severity7.5NVD Advisory· Published Sep 27, 2019· Updated Jun 17, 2026
CVE-2019-16902
CVE-2019-16902
Description
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- WordPress/ARforms plugindescription
- cpe:2.3:a:reputeinfosystems:arforms:3.7.1:*:*:*:*:wordpress:*:*
Patches
Vulnerability mechanics
References
2- almorabea.net/cve-2019-16902.txtnvdThird Party Advisory
- www.arformsplugin.com/documentation/changelog/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.