Description
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
Published: 2026-07-23
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Kali Forms plugin for WordPress versions 2.4.18 and older contains a flaw that lets a subscriber-level user delete any file on the server by manipulating the form handling logic. This loss of file integrity can remove critical application files or sensitive data, causing site downtime and data loss. The underlying weakness is a path traversal or arbitrary file deletion problem classified as CWE-22.

Affected Systems

WordPress installations running the Kali Forms plugin from WP Chill with version 2.4.18 or earlier are affected. Any site that has not yet updated the plugin is vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 7.7, indicating high severity, while the EPSS score of less than 1% suggests that exploit attempts are currently uncommon. Based on the description, it is inferred that attackers can trigger the flaw through a crafted form submission that a subscriber can execute remotely via an HTTP request to the plugin’s endpoint. No elevated privileges beyond those available to a standard subscriber are required. The plugin is not listed in the CISA KEV catalog, indicating no known widespread exploitation.

Generated by OpenCVE AI on August 3, 2026 at 22:19 UTC.

Remediation

Vendor Solution

Update the WordPress Kali Forms Plugin to the latest available version (at least 2.4.19).


OpenCVE Recommended Actions

  • Update the Kali Forms plugin to version 2.4.19 or later.
  • Temporarily disable the Kali Forms plugin until the plugin directory and critical application files are owned by the web server user and have restrictive permissions (e.g., 644 or 640).
  • Monitor web server logs for anomalous file deletion events.

Generated by OpenCVE AI on August 3, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Chill
Wp Chill kali Forms
Vendors & Products Wordpress
Wordpress wordpress
Wp Chill
Wp Chill kali Forms
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
Title WordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Wordpress Wordpress
Wp Chill Kali Forms
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T15:59:52.700Z

Reserved: 2026-07-05T21:27:56.024Z

Link: CVE-2026-59542

cve-icon Vulnrichment

Updated: 2026-07-23T15:59:48.403Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:33.067

Modified: 2026-07-23T16:17:29.853

Link: CVE-2026-59542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:30:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')