Unauthenticated Arbitrary Post Deletion in Kali Forms Plugin for WordPress
CVE-2020-36712

8.6HIGH

What is CVE-2020-36712?

The Kali Forms plugin for WordPress is susceptible to a vulnerability that allows unauthenticated users to delete any post or page. This occurs because the kaliforms_form_delete_uploaded_file function does not enforce any user privileges, enabling attackers to exploit this flaw by manipulating the ID parameter to target specific posts. The issue affects all versions of the plugin up to and including 2.1.1, which could lead to significant data loss and disruption for site owners.

Affected Version(s)

Kali Forms β€” Contact Form & Drag-and-Drop Builder 0 < 2.1.2

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jerome Bruandet
.