Impact
The vulnerability is an unauthenticated broken access control flaw in the Kali Forms plugin for WordPress, allowing an attacker to access administrative functions or content that should be restricted. Based on the description, it is inferred that the likely attack vector is by sending unauthenticated requests to protected endpoints. The flaw is a direct injection of the CWE-862 weakness, and an attacker could read or modify forms, inject malicious content, or otherwise compromise confidentiality and integrity of the site.
Affected Systems
All releases of WP Chill’s Kali Forms plugin up to and including version 2.4.23 are affected; no other vendors or products are listed.
Risk and Exploitability
The CVSS score is 5.3, indicating medium severity. The EPSS score is not available, so the exploitation likelihood cannot be quantified. The bug is not listed in CISA’s KEV catalog. Because it permits unauthenticated access, the flaw can be exploited remotely from any IP address with no credentials needed. Until the plugin is updated, the site remains exposed to attacks.
OpenCVE Enrichment