Junglewise Threat Intelligence

CVE-2026-81276: Kali Forms broken access control

CVE-2026-81276 · Severity: medium · CVSS 5.3 · Published 2026-08-27

Technologies: Kali Forms. Vendors: Kali Forms.

Executive brief

Kali Forms is a WordPress form-builder plugin used to create contact forms and data collection pages. A broken access control vulnerability allows unauthenticated users to view or modify form data and pages they should not have permission to access, potentially exposing sensitive information submitted through forms.

Technical details

The vulnerability is a broken access control flaw in Kali Forms versions up to and including 2.4.23, affecting the WordPress plugin. The issue allows unauthenticated attackers to access restricted pages or perform unauthorized actions without requiring authentication. No specific technical preconditions are documented beyond the ability to reach the affected plugin endpoints over the network. An attacker can exploit this to view or modify form data and access control-protected content. The vulnerability has been patched in version 2.4.24 and later.

Affected products

  • Kali Forms Kali Forms <=2.4.23

Timeline

  • 2026-08-26: disclosed: Published by Patchstack
  • 2026-08-26: patched: Version 2.4.24 patched the vulnerability

References

Related threats