Extension WordPress
Vulnérabilités Kali Forms , Contact Form & Drag-and-Drop Builder
Cette page rassemble les failles publiées pour Kali Forms , Contact Form & Drag-and-Drop Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Kali Forms , Contact Form & Drag-and-Drop Builder
13 fiches
Kali Forms <= 2.4.18 – Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value
The Kali Forms , Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping.…
*-2.4.18
2.4.19
16/07/2026
Kali Forms <= 2.4.13 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter
The Kali Forms , Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping.…
*-2.4.13
2.4.14
30/06/2026
Kali Forms <= 2.4.9 – Unauthenticated Remote Code Execution via form_process
The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder…
*-2.4.9
2.4.10
20/03/2026
Kali Forms <= 2.4.8 – Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure
The Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.8. This is due to the `get_items_permissions_check()` permission callback on the `/kaliforms/v1/forms/{id}` REST API endpoint only checking for…
*-2.4.8
2.4.9
17/02/2026
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.4.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping.…
*-2.4.2
2.4.3
25/04/2025
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 – Missing Authorization
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in…
*-2.3.41
2.3.42
19/02/2024
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 – Missing Authorization to Arbitrary Plugin Deactivation
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and…
*-2.3.41
2.3.42
19/02/2024
Contact Form builder with drag & drop – Kali Forms <= 2.3.36 – Insecure Direct Object Reference
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.36 due to missing validation on a user…
*-2.3.36
2.3.37
17/01/2024
Contact Form builder with drag & drop – Kali Forms <= 2.3.27 – Missing Authorization via Contact Form
The Contact Form builder with drag & drop – Kali Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing check on the run_form_process_checks function in versions up to, and including, 2.3.27. This…
*-2.3.27
2.3.28
16/10/2023
Contact Form builder with drag & drop – Kali Forms <= 2.3.28 – Missing Authorization via get_log
The Contact Form builder with drag & drop – Kali Forms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the get_log function in versions up to, and including, 2.3.28. This makes…
*-2.3.28
2.3.29
06/10/2023
Kali Forms <= 2.1.1 – Cross-Site Request Forgery
The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to…
[*, 2.1.2)
2.1.2
21/08/2020
Kali Forms <= 2.1.1 – Missing Authorization to Settings Update
The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to…
[*, 2.1.2)
2.1.2
21/08/2020
Kali Forms <= 2.1.1 – Unauthenticated Arbitrary Post Deletion
The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for…
[*, 2.1.2)
2.1.2
21/08/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.