Description
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
Published: 2026-08-27
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control flaw in the Kali Forms plugin for WordPress, allowing an attacker to access administrative functions or content that should be restricted. Based on the description, it is inferred that the likely attack vector is by sending unauthenticated requests to protected endpoints. The flaw is a direct injection of the CWE-862 weakness, and an attacker could read or modify forms, inject malicious content, or otherwise compromise confidentiality and integrity of the site.

Affected Systems

All releases of WP Chill’s Kali Forms plugin up to and including version 2.4.23 are affected; no other vendors or products are listed.

Risk and Exploitability

The CVSS score is 5.3, indicating medium severity. The EPSS score is not available, so the exploitation likelihood cannot be quantified. The bug is not listed in CISA’s KEV catalog. Because it permits unauthenticated access, the flaw can be exploited remotely from any IP address with no credentials needed. Until the plugin is updated, the site remains exposed to attacks.

Generated by OpenCVE AI on August 27, 2026 at 11:06 UTC.

Remediation

Vendor Solution

Update the WordPress Kali Forms Plugin to the latest available version (at least 2.4.24).


OpenCVE Recommended Actions

  • Upgrade the Kali Forms plugin to version 2.4.24 or later.
  • If an upgrade cannot be performed immediately, deactivate the plugin to eliminate the attack surface until a fix is available.
  • Implement a web application firewall or restrict access to the form endpoints to block unauthorized requests.

Generated by OpenCVE AI on August 27, 2026 at 11:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Chill
Wp Chill kali Forms
Vendors & Products Wordpress
Wordpress wordpress
Wp Chill
Wp Chill kali Forms

Thu, 27 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
Title WordPress Kali Forms plugin <= 2.4.23 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wp Chill Kali Forms
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-27T09:00:09.884Z

Reserved: 2026-08-26T17:33:04.627Z

Link: CVE-2026-81276

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T10:16:39.427

Modified: 2026-08-27T10:16:39.427

Link: CVE-2026-81276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T11:15:18Z

Weaknesses