Description
WordPress Plugin ARForms:Wordpress Form Builder is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin ARForms:Wordpress Form Builder version 3.5.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.5.2 or latest
References
Related Vulnerabilities
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more Security Bypass (1.7.29)
WordPress Plugin WP Survey And Quiz Tool 'rowcount' Parameter Cross-Site Scripting (2.9.2)
WordPress 3.7.x Cross-Domain Flash Injection Vulnerability (3.7 - 3.7.24)
WordPress Plugin Portfolio Gallery-Photo Gallery Cross-Site Scripting (2.2.2)
WordPress Plugin Slideshow Gallery 2 'border' Parameter Cross-Site Scripting (1.1.4)