WordPress Kali Forms是WordPress基金会的一个表单插件。 WordPress Kali Forms 2.4.17之前版本存在任意文件上传漏洞,该漏洞源于文件上传时未验证表单是否存在,允许未经身份验证的用户上传文件到WordPress媒体库,但上传仅限于WordPress默认允许的MIME类型,因此不会导致代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Kali Forms — Contact Form & Drag-and-Drop Builder | < 2.4.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Kali Forms — Contact Form & Drag-and-Drop Builder | 0 ~ 2.4.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11580 | Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR | |
| CVE-2026-12281 | Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Sp | |
| CVE-2026-12512 | Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter |
No comments yet