CVE-2023-45275: WordPress Contact Form builder with drag & drop plugin <= 2.3.28 - Broken Access Control vulnerability
Published Jan 2, 2025
·Updated
Missing Authorization vulnerability in WP Chill Kali Forms kali-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kali Forms: from n/a through <= 2.3.28.
Affected Software
1 affected component
wordpress/kali-forms<=2.3.28
Remediation
Information
No patched version is available.
Event History
Jan 2, 2025
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-45275?
CVE-2023-45275 is classified as a critical vulnerability due to its potential for unauthorized access to sensitive data.
2
How do I fix CVE-2023-45275?
To fix CVE-2023-45275, update the Kali Forms Contact Form builder to the latest version beyond 2.3.28.
3
What software is affected by CVE-2023-45275?
CVE-2023-45275 affects the Kali Forms Contact Form builder version 2.3.28 and below.
4
What type of vulnerability is CVE-2023-45275?
CVE-2023-45275 is a Missing Authorization vulnerability resulting from incorrectly configured access control measures.
5
Can CVE-2023-45275 impact user data?
Yes, CVE-2023-45275 can potentially expose sensitive user data due to its exploitation of access control flaws.