← WordPress Vulnerabilities
WordPress security by component

Kali Forms — Contact Form & Drag-and-Drop Builder

Kali Forms — Contact Form & Drag-and-Drop Builder is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 15, 2026; the highest CVE/CNA score is 5.9.

Plugin slug: kali-forms-contact-form-drag-and-drop-builder

CVE-2026-11580: Kali Forms — Contact Form & Drag-and-Drop Builder: A security weakness

Kali Forms — Contact Form & Drag-and-Drop Builder is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.4.17.

PublishedJul 15, 2026
Known safe version2.4.17
Safe version
Jul 15, 2026 CVE-2026-11580
Kali Forms — Contact Form & Drag-and-Drop Builder: A security weakness
Kali Forms — Contact Form & Drag-and-Drop Builder is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.4.17.
2.4.17
CVE5.5
NVDPending
Jul 15, 2026 CVE-2026-11579
Kali Forms — Contact Form & Drag-and-Drop Builder: A security weakness
Kali Forms — Contact Form & Drag-and-Drop Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.4.17.
2.4.17
CVE5.3
NVDPending
Jun 30, 2026 CVE-2026-11581
Kali Forms — Contact Form & Drag-and-Drop Builder: A security weakness
Kali Forms — Contact Form & Drag-and-Drop Builder is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 2.4.13.
2.4.13
CVE5.9
NVDPending