Missing Authorization
10 records55.6%First: 2020. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 18 vulnerability records associated with Kali Forms — Contact Form & Drag-and-Drop Builder, published between 2020 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2020 | 3 | |
| 2023 | 2 | |
| 2024 | 3 | |
| 2025 | 1 | |
| 2026 | 9 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 5.6% |
| High | 8 | 44.4% |
| Medium | 9 | 50% |
First: 2020. Latest: 2026.
First: 2025. Latest: 2026.
First: 2026. Latest: 2026.
First: 2020. Latest: 2020.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.4.212.4.192.4.142.4.172.4.102.4.92.4.32.3.422.3.372.3.282.3.292.1.2Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.4.20 | Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter | July 31, 2026 | 2.4.21 | High |
*-2.4.18 | Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting | July 27, 2026 | 2.4.19 | High |
*-2.4.18 | Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.18 - Authenticated (Subscriber+) Arbitrary File Deletion | July 22, 2026 | 2.4.19 | High |
*-2.4.18 | Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value | July 16, 2026 | 2.4.19 | High |
*-2.4.13 | Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter | June 30, 2026 | 2.4.14 | Medium |
*-2.4.16 | Kali Forms <= 2.4.16 - Missing Authorization to Unauthenticated Media File Upload | June 24, 2026 | 2.4.17 | Medium |
*-2.4.16 | Kali Forms <= 2.4.16 - Authenticated (Contributor+) Insecure Direct Object Reference to Post Metadata Disclosure | June 24, 2026 | 2.4.17 | Medium |
*-2.4.9 | Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process | March 20, 2026 | 2.4.10 | Critical |
*-2.4.8 | Kali Forms <= 2.4.8 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure | February 17, 2026 | 2.4.9 | Medium |
*-2.4.2 | Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | April 25, 2025 | 2.4.3 | Medium |
*-2.3.41 | Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization | February 19, 2024 | 2.3.42 | Medium |
*-2.3.41 | Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation | February 19, 2024 | 2.3.42 | High |
*-2.3.36 | Contact Form builder with drag & drop - Kali Forms <= 2.3.36 - Insecure Direct Object Reference | January 17, 2024 | 2.3.37 | Medium |
*-2.3.27 | Contact Form builder with drag & drop - Kali Forms <= 2.3.27 - Missing Authorization via Contact Form | October 16, 2023 | 2.3.28 | Medium |
*-2.3.28 | Contact Form builder with drag & drop - Kali Forms <= 2.3.28 - Missing Authorization via get_log | October 6, 2023 | 2.3.29 | Medium |
[*, 2.1.2) | Kali Forms <= 2.1.1 - Cross-Site Request Forgery | August 21, 2020 | 2.1.2 | High |
[*, 2.1.2) | Kali Forms <= 2.1.1 - Missing Authorization to Settings Update | August 21, 2020 | 2.1.2 | High |
[*, 2.1.2) | Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post Deletion | August 21, 2020 | 2.1.2 | High |
Selected source records
Published: July 31, 2026
Published: July 27, 2026
Published: July 22, 2026
Published: July 16, 2026
Published: June 30, 2026
Published: June 24, 2026
Published: June 24, 2026
Published: March 20, 2026
Published: March 20, 2026
Published: August 21, 2020
Published: August 21, 2020
Published: July 22, 2026
Published: July 31, 2026
Published: February 19, 2024
Published: July 27, 2026
Published: July 16, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.