VYPR

Kali Forms

by WordPress

Source repositories

CVEs (18)

  • CVE-2026-3584CriMar 20, 2026
    risk 0.57cvss 9.8epss 0.07

    The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined…

  • CVE-2020-36717HigJun 7, 2023
    risk 0.57cvss 8.8epss 0.00

    The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's…

  • CVE-2020-36712HigJun 7, 2023
    risk 0.56cvss 8.6epss 0.01

    The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for…

  • CVE-2026-16144HigAug 1, 2026
    risk 0.53cvss 8.1epss 0.01

    The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it…

  • CVE-2024-22305HigJan 31, 2024
    risk 0.49cvss 7.5epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.

  • CVE-2020-36720HigJun 7, 2023
    risk 0.46cvss 7.1epss 0.01

    The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the…

  • CVE-2023-45275MedJan 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.28.

  • CVE-2024-1217HigFeb 29, 2024
    risk 0.42cvss 7.6epss 0.00

    The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it…

  • CVE-2023-46083MedJan 2, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.27.

  • CVE-2026-1860MedFeb 18, 2026
    risk 0.21cvss 4.3epss 0.00

    The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.8. This is due to the `get_items_permissions_check()` permission callback on the `/kaliforms/v1/forms/{id}` REST API endpoint only checking for the…

  • CVE-2024-1218MedFeb 29, 2024
    risk 0.21cvss 4.3epss 0.00

    The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This…

  • CVE-2026-65446HigJul 27, 2026
    risk 0.00cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

  • CVE-2026-59542HigJul 23, 2026
    risk 0.00cvss 7.7epss 0.00

    Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.

  • CVE-2026-15395HigJul 17, 2026
    risk 0.00cvss 7.2epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-11580MedJul 15, 2026
    risk 0.00cvss 5.5epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type,…

  • CVE-2026-11579MedJul 15, 2026
    risk 0.00cvss 5.3epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows…

  • CVE-2026-9107MedJul 1, 2026
    risk 0.00cvss 6.4epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping.…

  • CVE-2026-11581MedJun 30, 2026
    risk 0.00cvss 5.9epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store…