7.5
CVSSv3

CVE-2019-16902

Published: 27/09/2019 Updated: 21/07/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

reputeinfosystems arforms 3.7.1

Exploits

WordPress Arforms plugin version 371 suffers from a directory traversal vulnerability ...

Github Repositories

This is the arbitrary file deletion for the Arforms Exploit version 3.7.1

Exploit Title: WordPress Arforms - 371 CVE ID: CVE-2019-16902 Date: 2019-09-27 Exploit Author: Ahmad Almorabea Author Website: almorabeanet Author Twitter: @almorabea Updated version of the exploit can be found always at : almorabeanet/cve-2019-16902txt Software Link: wwwarformsplugincom/documentation/changelog/ Version: 371 #Start Notes You can r