CVE-2019-16902: Reputeinfosystems Arforms
High severity, CVSS 7.5. EPSS: 9.7% chance of exploitation in the next 30 days.
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an arbitrary file by supplying the full pathname.
Affected products
- Reputeinfosystems Arforms: version 3.7.1 only
Published 2019-09-27. Last modified 2026-06-17.