Contact Form builder with drag & drop for WordPress – Kali Forms: A security weakness
Contact Form builder with drag & drop for WordPress – Kali Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
- Component
- Contact Form builder with drag & drop for WordPress – Kali Forms
- Plugin slug
kali-forms- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Jan 31, 2024
This CVE was published Jan 31, 2024 and is one of 12 known issues for this plugin.
Patch or disable the affected component.
Update Contact Form builder with drag & drop for WordPress – Kali Forms to a release outside the affected range, or disable and remove it until a fixed version is available.
Technical description
Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NVD vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N