Missing Authorization in Kali Forms Contact Form Builder by WPForms
CVE-2023-45275

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 January 2025

What is CVE-2023-45275?

A missing authorization vulnerability in the Kali Forms plugin allows attackers to exploit incorrectly configured access control security levels. This issue primarily impacts the drag and drop Contact Form builder functionality. Affected versions range from n/a through 2.3.28, making it critical for users to ensure proper access controls and configurations are in place to prevent unauthorized actions.

Affected Version(s)

Kali Forms 0 <= 2.3.28

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafshanzani Suhada (Patchstack Alliance)
.