The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with contributor access and higher, to obtain access to or modify forms or entries.
References
Configurations
History
19 Jan 2025, 02:53
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/changeset/3036466/kali-forms/trunk?contextall=1&old=3029334&old_path=%2Fkali-forms%2Ftrunk - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/ed1aae32-6040-4c42-b8a7-4c3be371a8c0?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:kaliforms:contact_form_builder:*:*:*:*:*:wordpress:*:* | |
CWE | NVD-CWE-noinfo | |
First Time |
Kaliforms contact Form Builder
Kaliforms |
21 Nov 2024, 08:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/changeset/3036466/kali-forms/trunk?contextall=1&old=3029334&old_path=%2Fkali-forms%2Ftrunk - | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/ed1aae32-6040-4c42-b8a7-4c3be371a8c0?source=cve - |
29 Feb 2024, 01:43
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-29 01:43
Updated : 2025-01-19 02:53
NVD link : CVE-2024-1218
Mitre link : CVE-2024-1218
CVE.ORG link : CVE-2024-1218
JSON object : View
Products Affected
kaliforms
- contact_form_builder
CWE