WordPress security changelog
HIGH CVE-2024-22305 Modified

Contact Form builder with drag & drop for WordPress – Kali Forms: A security weakness

Contact Form builder with drag & drop for WordPress – Kali Forms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.

CVE / CNA score 7.5 CVSS 3.1 · audit@patchstack.com
NVD score 8.1 CVSS 3.1 · nvd@nist.gov
Component
Contact Form builder with drag & drop for WordPress – Kali Forms
Plugin slug
kali-forms
Affected
See vendor advisory
Safe version
See mitigation notes
Published
Jan 31, 2024
Weakness
CWE-639 — Authorization Bypass Through User-Controlled Key

This CVE was published Jan 31, 2024 and is one of 12 known issues for this plugin.

Patch or disable the affected component.

Update Contact Form builder with drag & drop for WordPress – Kali Forms to a release outside the affected range, or disable and remove it until a fixed version is available.

Technical description

Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

NVD vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Primary and upstream sources