🔐 CVE Alert

CVE-2024-1218

MEDIUM 4.3

Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with contributor access and higher, to obtain access to or modify forms or entries.

CWE CWE-862
Vendor wpchill
Product kali forms — contact form & drag-and-drop builder
Published Feb 20, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for wpchill kali forms — contact form & drag-and-drop builder

Be the first to know when new medium vulnerabilities affecting wpchill kali forms — contact form & drag-and-drop builder are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

wpchill / Kali Forms — Contact Form & Drag-and-Drop Builder
0 ≤ 2.3.41

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/ed1aae32-6040-4c42-b8a7-4c3be371a8c0?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3036466/kali-forms/trunk?contextall=1&old=3029334&old_path=%2Fkali-forms%2Ftrunk

Credits

Lucio Sá