Unauthenticated Arbitrary Post Deletion in Kali Forms Plugin for WordPress
CVE-2020-36712
8.6HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 June 2023
What is CVE-2020-36712?
The Kali Forms plugin for WordPress is susceptible to a vulnerability that allows unauthenticated users to delete any post or page. This occurs because the kaliforms_form_delete_uploaded_file function does not enforce any user privileges, enabling attackers to exploit this flaw by manipulating the ID parameter to target specific posts. The issue affects all versions of the plugin up to and including 2.1.1, which could lead to significant data loss and disruption for site owners.
Affected Version(s)
Kali Forms β Contact Form & Drag-and-Drop Builder 0 < 2.1.2