Impact
The Kali Forms WordPress plugin does not sanitize form field captions before rendering them as column headers on the administrator form‑entries screen, allowing a user with the Contributor role or higher to inject and store JavaScript that executes in an administrator’s session. A missing capability check in the plugin’s post‑duplication action further lets a Contributor publish the malicious form, so an administrator who opens or duplicates that form renders the payload.
Affected Systems
WordPress sites that use Kali Forms version 2.4.12 or earlier. Any authenticated user with the Contributor role or higher can trigger the flaw, which affects the form‑entry administration area and the form publication process.
Risk and Exploitability
The flaw is exploitable by authenticated users with Contributor or higher roles, giving the attacker the ability to execute arbitrary JavaScript in the context of an administrator. An attacker could deface the site, exfiltrate data, or launch further attacks against internal resources. The CVSS score of 5.9 indicates moderate risk for this type of XSS vulnerability. The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, suggesting a low likelihood of widespread exploitation at the time of analysis.
OpenCVE Enrichment