cleantalk
Vulnerabilities and Security Researches

Contact Form builder with drag & drop for WordPress – Kali Forms, CVE-2020-36720

CVE, Research URL

CVE-2020-36720

Published on
Jun 07, 2023
Research Description
The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.
Affected versions
max 2.1.2.
Status
vulnerable