CVE-2024-1217
29.02.2024, 01:43
The Contact Form builder with drag & drop for WordPress Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it possible for authenticated attackers, with subscriber access or higher, to deactivate any active plugins.Enginsight
Vendor | Product | Version |
---|---|---|
kaliforms | contact_form_builder | 𝑥 < 2.3.42 |
𝑥
= Vulnerable software versions
References