Impact
Kali Forms – Contact Form & Drag‑and‑Drop Builder for WordPress is vulnerable to a stored cross‑site scripting flaw via the 'digitalSignature' field. The plugin fails to sanitize or escape input before saving it, so an attacker can place arbitrary JavaScript into the field. When a page that displays the stored submission is viewed, the script runs in the victim’s browser, allowing theft of cookies or session data, defacement, or redirection to malicious sites. The weakness corresponds to CWE‑79.
Affected Systems
All released versions of Kali Forms up to and including 2.4.18 are affected. The vulnerability applies when the plugin’s form shortcode is embedded on any page, as the form‑submission nonce is publicly visible.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. The EPSS score of <1% signals a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit it from any internet‑reachable location without authentication by submitting a crafted form on any page that contains the form shortcode, making the impact widespread among users of the affected site.
OpenCVE Enrichment