Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kali Forms < 2.4.17 - Unauthenticated Media Upload
Vulnerability Description
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Kali Forms 任意文件上传漏洞
Vulnerability Description
WordPress Kali Forms是WordPress基金会的一个表单插件。 WordPress Kali Forms 2.4.17之前版本存在任意文件上传漏洞,该漏洞源于文件上传时未验证表单是否存在,允许未经身份验证的用户上传文件到WordPress媒体库,但上传仅限于WordPress默认允许的MIME类型,因此不会导致代码执行。
CVSS Information
N/A
Vulnerability Type
N/A