CVE-2025-3201
- EPSS 0.07%
- Veröffentlicht 16.05.2025 06:15:46
- Zuletzt bearbeitet 27.05.2025 19:50:29
The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.
CVE-2024-22305
- EPSS 0.1%
- Veröffentlicht 31.01.2024 12:16:05
- Zuletzt bearbeitet 21.11.2024 08:56:01
Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36....
CVE-2020-36717
- EPSS 0.31%
- Veröffentlicht 07.06.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:30:08
The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1. This is due to incorrect nonce handling throughout the plugin's function. This makes it possible for unauthenticated attackers to...
CVE-2020-36720
- EPSS 0.24%
- Veröffentlicht 07.06.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:30:09
The Kali Forms plugin for WordPress is vulnerable to Authenticated Options Change in versions up to, and including, 2.1.1. This is due to the update_option lacking proper authentication checks. This makes it possible for any authenticated attacker to...
CVE-2020-36712
- EPSS 0.27%
- Veröffentlicht 07.06.2023 02:15:11
- Zuletzt bearbeitet 21.11.2024 05:30:08
The Kali Forms plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 2.1.1. This is due to the kaliforms_form_delete_uploaded_file function lacking any privilege or user protections. This make...