CVE-2024-1217
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins.
El complemento Contact Form builder with drag & drop for WordPress – Kali Forms para WordPress es vulnerable a la desactivación no autorizada del complemento debido a una falta de verificación de capacidad en la función await_plugin_deactivation en todas las versiones hasta la 2.3.41 incluida. Esto hace posible que atacantes autenticados, con acceso de suscriptor o superior, desactiven cualquier complemento activo.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-02 CVE Reserved
- 2024-02-19 CVE Published
- 2024-08-01 CVE Updated
- 2025-01-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kaliforms Search vendor "Kaliforms" | Contact Form Builder With Drag & Drop For WordPress – Kali Forms Search vendor "Kaliforms" for product "Contact Form Builder With Drag & Drop For WordPress – Kali Forms" | <= 2.3.41 Search vendor "Kaliforms" for product "Contact Form Builder With Drag & Drop For WordPress – Kali Forms" and version " <= 2.3.41" | en |
Affected
|