CVE-2024-22305
WordPress Contact Form builder with drag & drop - Kali Forms Plugin <= 2.3.36 is vulnerable to Insecure Direct Object References (IDOR)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.
Vulnerabilidad de omisión de autorización a través de clave controlada por el usuario en ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms. Este problema afecta a Contact Form builder with drag & drop for WordPress – Kali Forms: desde n/a hasta 2.3.36.
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.36 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access objects they do not have proper authorization to view.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2024-01-08 CVE Reserved
- 2024-01-17 CVE Published
- 2024-08-01 CVE Updated
- 2024-12-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/kali-forms/wordpress-kali-forms-plugin-2-3-38-insecure-direct-object-references-idor-vulnerability?_s_id=cve | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Kaliforms Search vendor "Kaliforms" | Kali Forms Search vendor "Kaliforms" for product "Kali Forms" | < 2.3.37 Search vendor "Kaliforms" for product "Kali Forms" and version " < 2.3.37" | wordpress |
Affected
|