Security Advisory

CVE-2020-36720

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-06-07 01:51:34
Last updated 2026-04-08 17:11:49
Assigner Wordfence
CVSS score 7.1
State PUBLISHED

Description

The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.