Report
The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.3.36 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access objects they do not have proper authorization to view.
Score:7.5
Severity:High
Version: 2.3.36
There is a patch available in v2.3.37 and we strongly recommend you update to this version as soon as possible.