Unauthorized Plugin Deactivation Vulnerability in Kali Forms Plugin for WordPress
CVE-2024-1217
7.6HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 February 2024
What is CVE-2024-1217?
The Kali Forms plugin for WordPress, known for its drag-and-drop contact form builder capabilities, is affected by a vulnerability that allows authenticated users with subscriber access or higher to deactivate any active plugins. This issue arises from a missing capability check in the await_plugin_deactivation function present in all versions up to and including 2.3.41. Attackers exploiting this vulnerability can disrupt website functionality and compromise site security.
Affected Version(s)
Kali Forms — Contact Form & Drag-and-Drop Builder 0 <= 2.3.41