Impact
The Kali Forms plugin for WordPress versions 2.4.18 and older contains a flaw that lets a subscriber-level user delete any file on the server by manipulating the form handling logic. This loss of file integrity can remove critical application files or sensitive data, causing site downtime and data loss. The underlying weakness is a path traversal or arbitrary file deletion problem classified as CWE-22.
Affected Systems
WordPress installations running the Kali Forms plugin from WP Chill with version 2.4.18 or earlier are affected. Any site that has not yet updated the plugin is vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 7.7, indicating high severity, while the EPSS score of less than 1% suggests that exploit attempts are currently uncommon. Based on the description, it is inferred that attackers can trigger the flaw through a crafted form submission that a subscriber can execute remotely via an HTTP request to the plugin’s endpoint. No elevated privileges beyond those available to a standard subscriber are required. The plugin is not listed in the CISA KEV catalog, indicating no known widespread exploitation.
OpenCVE Enrichment