WordPress security by component
Kali Forms
Plugin description
Kali Forms is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
kali-formsLatest vulnerability
CVE-2026-59542: Kali Forms: Arbitrary file deletion
Kali Forms is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is n/a through 2.4.18.
| Safe version |
|
||
|---|---|---|---|
| Jul 23, 2026 |
CVE-2026-59542
Kali Forms: Arbitrary file deletion
Kali Forms is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is n/a through 2.4.18.
|
2.4.19 |
CVE7.7
NVDPending
|
| Jul 17, 2026 |
CVE-2026-15395
Kali Forms signatures allow unauthenticated stored XSS
Kali Forms 2.4.18 and earlier stores digitalSignature field content without sufficient sanitization and later renders it without safe escaping. Because the form nonce is available on the public form, an unauthenticated attacker can submit persistent script that executes when the stored submission is viewed.
|
> 2.4.18 |
CVE7.2
NVDPending
|
| Jul 01, 2026 |
CVE-2026-9107
Kali Forms — Contact Form & Drag-and-Drop Builder: Cross-site scripting
Kali Forms — Contact Form & Drag-and-Drop Builder is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.4.13.
|
> 2.4.13 |
CVE6.4
NVDPending
|
| Mar 20, 2026 |
CVE-2026-3584
Kali Forms: Code execution
Kali Forms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Feb 18, 2026 |
CVE-2026-1860
Kali Forms: A security weakness
Kali Forms is affected by a security weakness. Exploitation requires at least contributor-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| May 16, 2025 |
CVE-2025-3201
Contact Form builder with drag & drop for WordPress: Cross-site scripting
Contact Form builder with drag & drop for WordPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Jan 02, 2025 |
CVE-2023-46083
Kali Forms: A security weakness
Kali Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 02, 2025 |
CVE-2023-45275
Kali Forms: A security weakness
Kali Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jan 31, 2024 |
CVE-2024-22305
Contact Form builder with drag & drop for WordPress – Kali Forms: A security weakness
Contact Form builder with drag & drop for WordPress – Kali Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD8.1
|
| Jun 07, 2023 |
CVE-2020-36720
Kali Forms: A security weakness
Kali Forms is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.1
NVD7.1
|
| Jun 07, 2023 |
CVE-2020-36717
Kali Forms: Cross-site request forgery
Kali Forms is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Jun 07, 2023 |
CVE-2020-36712
Kali Forms: A security weakness
Kali Forms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.6
NVD5.3
|