CVE-2020-36712

Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post Deletion

The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site post or page with the id parameter.


We have discovered 127 live websites that are affected by CVE-2020-36712.

Run a Free Instant Scan




Affected Software

Product  Kali Forms
Category Wordpress Plugins
Vulnerable Domains127 live websites (2.43% of Kali Forms install base)
Vulnerable Versions
  • from 0 through 2.1.2
Vulnerable Versions Count10 versions ( 12% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jun 7, 2023
  • Updated - Apr 8, 2026

Credits

  • Jerome Bruandet (finder)

Website Distribution by Country

Number of websites using CVE-2020-36712
United States26 websites



France17 websites
Germany11 websites
Czech Republic8 websites
Italy6 websites
Russia5 websites
GB4 websites
Australia4 websites
Brazil3 websites
Spain3 websites

Website Distribution by TLD

Number of websites using CVE-2020-36712
.com49 websites
.fr11 websites
.cz8 websites
.org7 websites
.ru4 websites
.de4 websites
.nl3 websites
.com.au3 websites
.com.br3 websites
.eu3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-36712

Top websites that are affected by CVE-2020-36712. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States*,***,***
*****.net United States*,***,***
*****.************.eu Spain*,***,***
********************.fr France*,***,***
***.**************.org United States*,***,***
**************.fr France*,***,***
*******************.org United States*,***,***
**************.fr France*,***,***
****.com China*,***,***
*****.com Israel**,***,***
See full domain list

FAQ

CVE-2020-36712 is Missing Authorization in Kali Forms
A total of 127 websites have been identified as vulnerable to CVE-2020-36712, based on global website indexing conducted by WebTechSurvey.
The Kali Forms is affected by the CVE-2020-36712 vulnerability.
Kali Forms versions up to 2.1.2 are vulnerable to CVE-2020-36712.
CVE-2020-36712 is resolved in version 2.1.2 of Kali Forms.