WordPress Plugin Vulnerabilities

Kali Forms < 2.4.17 - Unauthenticated Media Upload

Description

The plugin does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.

Proof of Concept

Affects Plugins

Fixed in 2.4.17

References

Miscellaneous

Original Researcher
Alexander Jurkschat
Submitter
Alexander Jurkschat
Verified
Yes

Timeline

Publicly Published
2026-06-24 (about 1 month ago)
Added
2026-06-24 (about 1 month ago)
Last Updated
2026-06-24 (about 1 month ago)

Other