wpchill Vulnerabilities and Affected Products
Vulnerabilities associated with Kali Forms — Contact Form & Drag-and-Drop Builder.
Products
Clear product- Download Monitor12 vulnerabilities
- Kali Forms — Contact Form & Drag-and-Drop Builder10 vulnerabilities
- Strong Testimonials7 vulnerabilities
- Modula Image Gallery – Photo Grid & Video Gallery6 vulnerabilities
- Image Photo Gallery Final Tiles Grid5 vulnerabilities
- Passster – Password Protect Pages and Content5 vulnerabilities
- download_monitor3 vulnerabilities
- Brilliance2 vulnerabilities
- Filr – Secure document library2 vulnerabilities
- Gallery PhotoBlocks (WordPress plugin)2 vulnerabilities
- Image Gallery – Photo Grid & Video Gallery2 vulnerabilities
- Qyrr – simply and modern QR-Code creation2 vulnerabilities
- Simple Restrict2 vulnerabilities
- simple_restrict2 vulnerabilities
- Affluent1 vulnerability
- Allegiant1 vulnerability
- CPO Companion1 vulnerability
- CPO Content Types1 vulnerability
- CPO Shortcodes1 vulnerability
- CPO Shortcodes (WordPress plugin)1 vulnerability
- Download Monitor (WordPress plugin)1 vulnerability
- Download Monitor plugin for WordPress1 vulnerability
- Gallery PhotoBlocks1 vulnerability
- imageseo1 vulnerability
- Lightbox – EverlightBox Gallery1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-16144HIGH | Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field ParameterThe Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires… CWE-94Aug 1, 2026 | CVSS8.1v3.1 | EPSS0.688% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-15395HIGH | Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field ValueThe Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The required form-submission nonce is publicly available on any page containing the f… CWE-79Jul 17, 2026 | CVSS7.2v3.1 | EPSS0.247% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9107MEDIUM | Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' ParameterThe Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter in all versions up to, and including, 2.4.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Jul 1, 2026 | CVSS6.4v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-3584CRITICAL | Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_processThe Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server. | CVSS9.8v3.1 | EPSS7.24% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-1860MEDIUM | Kali Forms <= 2.4.8 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data ExposureThe Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.8. This is due to the `get_items_permissions_check()` permission callback on the `/kaliforms/v1/forms/{id}` REST API endpoint only checking for the `edit_posts` capability without verifying that the requesting user has ownership or authorization over the specific form resource. This makes it possible for authenticated attackers, with Contributor-level access and above, … CWE-862Feb 18, 2026 | CVSS4.3v3.1 | EPSS0.289% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1218MEDIUM | Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing AuthorizationThe Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized access and modification of data via API due to an inconsistent capability check on several REST endpoints in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with contributor access and higher, to obtain access to or modify forms or entries. CWE-862Feb 20, 2024 | CVSS4.3v3.1 | EPSS0.308% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-1217HIGH | Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin DeactivationThe Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins. CWE-862Feb 20, 2024 | CVSS7.6v3.1 | EPSS0.306% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36717HIGH | Kali Forms <= 2.1.1 - Cross-Site Request ForgeryThe Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to access the plugin's administrative functions via forged request granted they can trick a site administrator into performing an action such as clicking on a link. CWE-352Jun 7, 2023 | CVSS8.8v3.1 | EPSS0.478% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36720HIGH | Kali Forms <= 2.1.1 - Missing Authorization to Settings UpdateThe Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to change (or delete) the plugin's settings. CWE-862Jun 7, 2023 | CVSS7.1v3.1 | EPSS0.793% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36712HIGH | Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post DeletionThe Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This makes it possible for unauthenticated attackers to delete any site post or page with the id parameter. CWE-862Jun 7, 2023 | CVSS8.6v3.1 | EPSS0.735% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |