CVE-2024-1218
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with contributor access and higher, to obtain access to or modify forms or entries.
El complemento Contact Form builder with drag & drop for WordPress – Kali Forms para WordPress es vulnerable al acceso no autorizado y a la modificación de datos a través de API debido a una verificación de capacidad inconsistente en varios puntos finales REST en todas las versiones hasta la 2.3.41 incluida. Esto hace posible que atacantes autenticados, con acceso de colaborador y superior, obtengan acceso o modifiquen formularios o entradas.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-02 CVE Reserved
- 2024-02-19 CVE Published
- 2024-08-01 CVE Updated
- 2025-01-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kaliforms Search vendor "Kaliforms" | Contact Form Builder With Drag & Drop For WordPress – Kali Forms Search vendor "Kaliforms" for product "Contact Form Builder With Drag & Drop For WordPress – Kali Forms" | <= 2.3.41 Search vendor "Kaliforms" for product "Contact Form Builder With Drag & Drop For WordPress – Kali Forms" and version " <= 2.3.41" | en |
Affected
|