cleantalk
Vulnerabilities and Security Researches

Contact Form builder with drag & drop for WordPress – Kali Forms, 897779ad1cfbd26184eae4404d2e5e00ceb73f4a

Published on
Aug 21, 2020
Research Description
Kali Forms — Contact Form &amp; Drag-and-Drop Builder [kali-forms] < 2.1.2 Kali Forms <= 2.1.1 - Missing Authorization to Settings Update The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.
Affected versions
max 2.1.2.
Status
vulnerable