plugin

Kali Forms Vulnerabilities

36 known security issues reported for the Kali Forms WordPress plugin. Most recent disclosed Jul 31, 2026.

1 critical 8 high 9 medium

Running Kali Forms on your site? Check whether your installed version is affected.

Scan your site free

Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter

high

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allow...

CVSS:
8.1
Affected:
up to 2.4.20
Fixed in:
2.4.21
Disclosed:
Jul 31, 2026

CVE-2026-16144 on NVD →

Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting

high

The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses a...

CVSS:
7.2
Affected:
up to 2.4.18
Fixed in:
2.4.19
Disclosed:
Jul 27, 2026

CVE-2026-65446 on NVD →

Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.18 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.4.18. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files...

CVSS:
8.1
Affected:
up to 2.4.18
Fixed in:
2.4.19
Disclosed:
Jul 22, 2026

CVE-2026-59542 on NVD →

Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value

high

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...

CVSS:
7.2
Affected:
up to 2.4.18
Fixed in:
2.4.19
Disclosed:
Jul 16, 2026

CVE-2026-15395 on NVD →

Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter

medium

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated a...

CVSS:
6.4
Affected:
up to 2.4.13
Fixed in:
2.4.14
Disclosed:
Jun 30, 2026

CVE-2026-9107 on NVD →

Kali Forms <= 2.4.16 - Missing Authorization to Unauthenticated Media File Upload

medium

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.4.16. This makes it possible for unauthenticated attackers to upload media files.

CVSS:
5.3
Affected:
up to 2.4.16
Fixed in:
2.4.17
Disclosed:
Jun 24, 2026

CVE-2026-11579 on NVD →

Kali Forms <= 2.4.16 - Authenticated (Contributor+) Insecure Direct Object Reference to Post Metadata Disclosure

medium

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to ex...

CVSS:
4.3
Affected:
up to 2.4.16
Fixed in:
2.4.17
Disclosed:
Jun 24, 2026

CVE-2026-11580 on NVD →

Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process

critical

The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on thes...

CVSS:
9.8
Affected:
up to 2.4.9
Fixed in:
2.4.10
Disclosed:
Mar 20, 2026

CVE-2026-3584 on NVD →

Kali Forms <= 2.4.8 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure

medium

The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.8. This is due to the `get_items_permissions_check()` permission callback on the `/kaliforms/v1/forms/{id}` REST API endpoint only checking for the `edit_posts` capability without verifying th...

CVSS:
4.3
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Feb 17, 2026

CVE-2026-1860 on NVD →

Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access...

CVSS:
6.4
Affected:
up to 2.4.2
Fixed in:
2.4.3
Disclosed:
Apr 25, 2025

CVE-2025-3201 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.3.28

unknown

[en] Missing Authorization vulnerability in Kali Forms Contact Form builder with drag & drop - Kali Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form builder with drag & drop - Kali Forms: from n/a through 2.3.27.

Affected:
up to 2.3.28
Fixed in:
2.3.28
Disclosed:
Jan 2, 2025

CVE-2023-46083 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.3.29

unknown

[en] Missing Authorization vulnerability in Kali Forms Contact Form builder with drag & drop - Kali Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form builder with drag & drop - Kali Forms: from n/a through 2.3.28.

Affected:
up to 2.3.29
Fixed in:
2.3.29
Disclosed:
Jan 2, 2025

CVE-2023-45275 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.3.42

unknown

[en] The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated at...

Affected:
up to 2.3.42
Fixed in:
2.3.42
Disclosed:
Feb 20, 2024

CVE-2024-1218 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.3.42

unknown

[en] The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, w...

Affected:
up to 2.3.42
Fixed in:
2.3.42
Disclosed:
Feb 20, 2024

CVE-2024-1217 on NVD →

Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation

high

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with s...

CVSS:
7.6
Affected:
up to 2.3.41
Fixed in:
2.3.42
Disclosed:
Feb 19, 2024

CVE-2024-1217 on NVD →

Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization

medium

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated attacke...

CVSS:
4.3
Affected:
up to 2.3.41
Fixed in:
2.3.42
Disclosed:
Feb 19, 2024

CVE-2024-1218 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.3.37

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.

Affected:
up to 2.3.37
Fixed in:
2.3.37
Disclosed:
Jan 31, 2024

CVE-2024-22305 on NVD →

Contact Form builder with drag & drop - Kali Forms <= 2.3.36 - Insecure Direct Object Reference

medium

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.36 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access objects they do not...

CVSS:
6.5
Affected:
up to 2.3.36
Fixed in:
2.3.37
Disclosed:
Jan 17, 2024

CVE-2024-22305 on NVD →

Contact Form builder with drag & drop - Kali Forms <= 2.3.27 - Missing Authorization via Contact Form

medium

The Contact Form builder with drag & drop - Kali Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing check on the run_form_process_checks function in versions up to, and including, 2.3.27. This makes it possible for unauthenticated attackers to submit forms even when they are...

CVSS:
5.3
Affected:
up to 2.3.27
Fixed in:
2.3.28
Disclosed:
Oct 16, 2023

CVE-2023-46083 on NVD →

Contact Form builder with drag & drop - Kali Forms <= 2.3.28 - Missing Authorization via get_log

medium

The Contact Form builder with drag & drop - Kali Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_log function in versions up to, and including, 2.3.28. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve the...

CVSS:
6.5
Affected:
up to 2.3.28
Fixed in:
2.3.29
Disclosed:
Oct 6, 2023

CVE-2023-45275 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

[en] The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Jun 7, 2023

CVE-2020-36717 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

[en] The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site po...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Jun 7, 2023

CVE-2020-36712 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

[en] The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Jun 7, 2023

CVE-2020-36720 on NVD →

Kali Forms <= 2.1.1 - Cross-Site Request Forgery

high

The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request grant...

CVSS:
8.8
Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 21, 2020

CVE-2020-36717 on NVD →

Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post Deletion

high

The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site post or...

CVSS:
8.6
Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 21, 2020

CVE-2020-36712 on NVD →

Kali Forms <= 2.1.1 - Missing Authorization to Settings Update

high

The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.

CVSS:
7.1
Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 21, 2020

CVE-2020-36720 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities discovered by NinTechNet in WordPress Contact Form builder with drag & drop plugin (versions <= 2.1.1).

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 21, 2020

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

Unauthenticated Arbitrary Post Deletion vulnerability discovered by NinTechNet in WordPress Contact Form builder with drag & drop plugin (versions <= 2.1.1).

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 21, 2020

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

Authenticated Plugin Settings Change vulnerability discovered by NinTechNet in WordPress Contact Form builder with drag & drop plugin (versions <= 2.1.1).

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 21, 2020

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request grant...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 21, 2020

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site post or...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 21, 2020

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings.

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Aug 21, 2020

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.4.3

unknown
Affected:
up to 2.4.3
Fixed in:
2.4.3

CVE-2025-3201 on NVD →

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

The plugin registers the kaliforms_form_delete_uploaded_file AJAX action to call the &quot;delete_file&quot; function, and makes it accessible to all users, authenticated or not

Affected:
up to 2.1.2
Fixed in:
2.1.2

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

Throughout the plugin&rsquo;s code, security nonces can be bypassed because they are only checked if they are set.

Affected:
up to 2.1.2
Fixed in:
2.1.2

Contact Form builder with drag &amp; drop for WordPress &#8211; Kali Forms [kali-forms] < 2.1.2

unknown

The kaliforms_update_option_ajax() AJAX action lacks capability and proper CSRF checks, allowing low privilege authenticated users to change or delete the plugin&#039;s settings.

Affected:
up to 2.1.2
Fixed in:
2.1.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database