Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter
high
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allow...
- CVSS:
- 8.1
- Affected:
- up to 2.4.20
- Fixed in:
- 2.4.21
- Disclosed:
- Jul 31, 2026
CVE-2026-16144 on NVD →
Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting
high
The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses a...
- CVSS:
- 7.2
- Affected:
- up to 2.4.18
- Fixed in:
- 2.4.19
- Disclosed:
- Jul 27, 2026
CVE-2026-65446 on NVD →
Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.18 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.4.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files...
- CVSS:
- 8.1
- Affected:
- up to 2.4.18
- Fixed in:
- 2.4.19
- Disclosed:
- Jul 22, 2026
CVE-2026-59542 on NVD →
Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value
high
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...
- CVSS:
- 7.2
- Affected:
- up to 2.4.18
- Fixed in:
- 2.4.19
- Disclosed:
- Jul 16, 2026
CVE-2026-15395 on NVD →
Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter
medium
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...
- CVSS:
- 6.4
- Affected:
- up to 2.4.13
- Fixed in:
- 2.4.14
- Disclosed:
- Jun 30, 2026
CVE-2026-9107 on NVD →
Kali Forms <= 2.4.16 - Missing Authorization to Unauthenticated Media File Upload
medium
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.16. This makes it possible for unauthenticated attackers to upload media files.
- CVSS:
- 5.3
- Affected:
- up to 2.4.16
- Fixed in:
- 2.4.17
- Disclosed:
- Jun 24, 2026
CVE-2026-11579 on NVD →
Kali Forms <= 2.4.16 - Authenticated (Contributor+) Insecure Direct Object Reference to Post Metadata Disclosure
medium
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to ex...
- CVSS:
- 4.3
- Affected:
- up to 2.4.16
- Fixed in:
- 2.4.17
- Disclosed:
- Jun 24, 2026
CVE-2026-11580 on NVD →
Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
critical
The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on thes...
- CVSS:
- 9.8
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.10
- Disclosed:
- Mar 20, 2026
CVE-2026-3584 on NVD →
Kali Forms <= 2.4.8 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure
medium
The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.8. This is due to the `get_items_permissions_check()` permission callback on the `/kaliforms/v1/forms/{id}` REST API endpoint only checking for the `edit_posts` capability without verifying th...
- CVSS:
- 4.3
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- Feb 17, 2026
CVE-2026-1860 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.3
- Disclosed:
- Apr 25, 2025
CVE-2025-3201 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.3.28
unknown
[en] Missing Authorization vulnerability in Kali Forms Contact Form builder with drag & drop - Kali Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form builder with drag & drop - Kali Forms: from n/a through 2.3.27.
- Affected:
- up to 2.3.28
- Fixed in:
- 2.3.28
- Disclosed:
- Jan 2, 2025
CVE-2023-46083 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.3.29
unknown
[en] Missing Authorization vulnerability in Kali Forms Contact Form builder with drag & drop - Kali Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form builder with drag & drop - Kali Forms: from n/a through 2.3.28.
- Affected:
- up to 2.3.29
- Fixed in:
- 2.3.29
- Disclosed:
- Jan 2, 2025
CVE-2023-45275 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.3.42
unknown
[en] The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated at...
- Affected:
- up to 2.3.42
- Fixed in:
- 2.3.42
- Disclosed:
- Feb 20, 2024
CVE-2024-1218 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.3.42
unknown
[en] The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, w...
- Affected:
- up to 2.3.42
- Fixed in:
- 2.3.42
- Disclosed:
- Feb 20, 2024
CVE-2024-1217 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation
high
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with s...
- CVSS:
- 7.6
- Affected:
- up to 2.3.41
- Fixed in:
- 2.3.42
- Disclosed:
- Feb 19, 2024
CVE-2024-1217 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization
medium
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated attacke...
- CVSS:
- 4.3
- Affected:
- up to 2.3.41
- Fixed in:
- 2.3.42
- Disclosed:
- Feb 19, 2024
CVE-2024-1218 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.3.37
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.
- Affected:
- up to 2.3.37
- Fixed in:
- 2.3.37
- Disclosed:
- Jan 31, 2024
CVE-2024-22305 on NVD →
Contact Form builder with drag & drop - Kali Forms <= 2.3.36 - Insecure Direct Object Reference
medium
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.36 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access objects they do not...
- CVSS:
- 6.5
- Affected:
- up to 2.3.36
- Fixed in:
- 2.3.37
- Disclosed:
- Jan 17, 2024
CVE-2024-22305 on NVD →
Contact Form builder with drag & drop - Kali Forms <= 2.3.27 - Missing Authorization via Contact Form
medium
The Contact Form builder with drag & drop - Kali Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing check on the run_form_process_checks function in versions up to, and including, 2.3.27. This makes it possible for unauthenticated attackers to submit forms even when they are...
- CVSS:
- 5.3
- Affected:
- up to 2.3.27
- Fixed in:
- 2.3.28
- Disclosed:
- Oct 16, 2023
CVE-2023-46083 on NVD →
Contact Form builder with drag & drop - Kali Forms <= 2.3.28 - Missing Authorization via get_log
medium
The Contact Form builder with drag & drop - Kali Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_log function in versions up to, and including, 2.3.28. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve the...
- CVSS:
- 6.5
- Affected:
- up to 2.3.28
- Fixed in:
- 2.3.29
- Disclosed:
- Oct 6, 2023
CVE-2023-45275 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
[en] The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Jun 7, 2023
CVE-2020-36717 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
[en] The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site po...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Jun 7, 2023
CVE-2020-36712 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
[en] The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Jun 7, 2023
CVE-2020-36720 on NVD →
Kali Forms <= 2.1.1 - Cross-Site Request Forgery
high
The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request grant...
- CVSS:
- 8.8
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 21, 2020
CVE-2020-36717 on NVD →
Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post Deletion
high
The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site post or...
- CVSS:
- 8.6
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 21, 2020
CVE-2020-36712 on NVD →
Kali Forms <= 2.1.1 - Missing Authorization to Settings Update
high
The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.
- CVSS:
- 7.1
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 21, 2020
CVE-2020-36720 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities discovered by NinTechNet in WordPress Contact Form builder with drag & drop plugin (versions <= 2.1.1).
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 21, 2020
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
Unauthenticated Arbitrary Post Deletion vulnerability discovered by NinTechNet in WordPress Contact Form builder with drag & drop plugin (versions <= 2.1.1).
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 21, 2020
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
Authenticated Plugin Settings Change vulnerability discovered by NinTechNet in WordPress Contact Form builder with drag & drop plugin (versions <= 2.1.1).
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 21, 2020
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request grant...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 21, 2020
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site post or...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 21, 2020
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 21, 2020
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.4.3
unknown
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
CVE-2025-3201 on NVD →
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
The plugin registers the kaliforms_form_delete_uploaded_file AJAX action to call the "delete_file" function, and makes it accessible to all users, authenticated or not
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
Throughout the plugin’s code, security nonces can be bypassed because they are only checked if they are set.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
Contact Form builder with drag & drop for WordPress – Kali Forms [kali-forms] < 2.1.2
unknown
The kaliforms_update_option_ajax() AJAX action lacks capability and proper CSRF checks, allowing low privilege authenticated users to change or delete the plugin's settings.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2