Kali Forms <= 2.4.8 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure
Kali Forms — Contact Form & Drag-and-Drop Builder
Minimum safe version
2.4.10
Update to 2.4.10 or later to address 20 fixable vulnerabilities
Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
WordPress Contact Form builder with drag & drop - Kali Forms Plugin < 2.4.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-1218
CVE-2024-1217
CVE-2024-22305
CVE-2023-46083
CVE-2023-45275
CVE-2020-36720
CVE-2020-36712
CVE-2020-36717
Contact Form - Form builder by Kali Forms < 2.1.2 - Unauthenticated Arbitrary Post Deletion
Contact Form - Form builder by Kali Forms < 2.1.2 - Multiple CSRF Bypass Issues
Contact Form - Form builder by Kali Forms < 2.1.2 - Authenticated Plugin's Settings Change
Kali Forms <= 2.1.1 - Cross-Site Request Forgery
Kali Forms <= 2.1.1 - Missing Authorization to Settings Update
Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post Deletion
WordPress Contact Form builder with drag & drop plugin <= 2.1.1 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
WordPress Contact Form builder with drag & drop plugin <= 2.1.1 - Authenticated Plugin Settings Change vulnerability
WordPress Contact Form builder with drag & drop plugin <= 2.1.1 - Unauthenticated Arbitrary Post Deletion vulnerability