CVE-2024-22305: Kaliforms Kali Forms

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form builder with drag & drop for WordPress – Kali Forms: from n/a through 2.3.36.

Affected products

  • Kaliforms Kali Forms: before 2.3.37 (fixed in 2.3.37)

Published 2024-01-31. Last modified 2026-06-17.