Impact
The Kali Forms WordPress plugin does not sanitize a form field’s caption before rendering it as a column header on the administrator form‑entries screen. Contributors or higher roles can embed JavaScript into these captions, resulting in stored XSS that executes in an administrator’s browser session. A missing capability check in the plugin’s post‑duplication action also allows a contributor to publish the malicious form, widening the attack surface.
Affected Systems
WordPress sites running Kali Forms version 2.4.12 or earlier. Any user with Contributor level or higher can trigger the exploitation, and the vulnerability affects the form‑entry administration area and form publication process.
Risk and Exploitability
The flaw is exploitable by authenticated users with Contributor or higher roles, who can inject JavaScript into form captions. Because the payload runs in the context of an administrator, an attacker could deface the site, exfiltrate data, or further target internal resources. EPSS is unavailable and the vulnerability is not listed in KEV, but the stored XSS nature of the flaw makes it a high‑risk issue for affected installations.
OpenCVE Enrichment