Junglewise Threat Intelligence

CVE-2026-59542: WP Chill Kali Forms arbitrary file deletion via path traversal

CVE-2026-59542 · Severity: high · CVSS 7.7 · Published 2026-07-23

Vendors: WP Chill.

Executive brief

Kali Forms, a popular WordPress plugin used for creating contact and registration forms, contains a security flaw that allows logged-in users with basic 'Subscriber' permissions to delete arbitrary files from the web server. This could lead to a complete website outage if critical system files are removed, or it could be used to bypass security controls by deleting configuration files. Administrators should update to version 2.4.19 or later immediately to prevent potential site disruption.

Technical details

The Kali Forms plugin for WordPress (versions 2.4.18 and below) is vulnerable to arbitrary file deletion due to improper limitation of a pathname to a restricted directory (CWE-22). An attacker authenticated with Subscriber-level privileges can exploit this path traversal vulnerability to delete files outside of the intended directory. By sending a specially crafted request, a remote attacker can delete critical WordPress core files or configuration files, leading to a Denial of Service (DoS) or further system compromise. The issue is resolved in version 2.4.19.

Affected products

  • WP Chill Kali Forms <= 2.4.18

Timeline

  • 2026-06-17: other: Vulnerability reported by researcher daroo
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset

References