CVE-2020-36720: Kaliforms Kali Forms
High severity, CVSS 7.1. EPSS: 0.8% chance of exploitation in the next 30 days.
The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.
Affected products
- Kaliforms Kali Forms: up to and including 2.1.1
Published 2023-06-07. Last modified 2026-06-17.