What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.
Explanation of Vulnerability in Simple Terms
02Summary
Kali Forms versions up to 2.3.36 expose sensitive form data without proper access controls. An unauthenticated attacker can read submitted form entries, including names, emails, and other user-provided information, by making direct requests to the plugin's data endpoints. This affects all sites running the vulnerable plugin version.
What an attacker can do
03Attacker Capabilities
Read submitted form entries and user data without authentication.
Potential impact on your site
04Site Impact
Form submissions (contact requests, inquiries, etc.) are exposed to anyone who discovers the vulnerable endpoint.
Conditions required to exploit
05Prerequisites
Network access to the WordPress site; no authentication or user interaction required.
Key dates
06Disclosure timeline
January 31, 2024
CVE published
April 28, 2026
Record updated