Impact
The vulnerability in Kali Forms allows a stored cross‑site scripting (XSS) flaw caused by insufficient sanitization and escaping of the meta[kaliforms_field_components] parameter. An attacker with contributor‑level or higher access can inject malicious scripts that will run whenever any user loads a page containing the affected form. This can lead to theft of session cookies, defacement, or further arbitrary code execution by exploiting browser trust. The weakness aligns with CWE‑79. The CVSS score of 6.4 reflects a moderate severity of the flaw.
Affected Systems
The issue affects the "Kali Forms – Contact Form & Drag‑and‑Drop Builder" plugin developed by wpchill. All releases up to and including version 2.4.13 are vulnerable; versions 2.4.14 onward contain the fix.
Risk and Exploitability
Because it requires authenticated access at the contributor level, the threat surface is limited to users with editing privileges. There is no known remote exploitation vector outside of logged‑in staff, and it is not listed in the CISA KEV catalog. The lack of an EPSS score does not reduce the need for patching, as the moderate CVSS indicates the potential for moderate damage if an attacker gains user login credentials or exploits a high‑privilege user session.
OpenCVE Enrichment