Impact
The Kali Forms WordPress plugin before version 2.4.17 fails to confirm that a file upload request is associated with a form that contains an allowed file‑upload field. As a result, any user can POST a file that passes WordPress’s default MIME type check to the Media Library. The flaw does not provide a path to execute code; it simply permits the addition of arbitrary media files.
Affected Systems
WordPress installations that have the Kali Forms – Contact Form & Drag‑and‑Drop Builder plugin installed in any version earlier than 2.4.17. Administrators who have updated to v2.4.17 or newer are no longer affected because the check for a corresponding form has been fixed.
Risk and Exploitability
The CVSS base score of 5.3 categorizes this as a moderate severity vulnerability, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. Attackers can exploit it by targeting the plugin’s upload endpoint with an unauthenticated HTTP request, without requiring any privileges or system access. Because uploads are limited to WordPress’s default allowed MIME types, the risk is confined to unauthorized media library contamination and does not lead to remote code execution. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment