CVE-2026-81276: WordPress Kali Forms plugin <= 2.4.23 - Broken Access Control vulnerability
Published Aug 27, 2026
·Updated
Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.
Affected Software
1 affected component
wordpress/kali-forms<=2.4.23
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Kali Forms Pluginto a version that resolves this vulnerability.Fixed in 2.4.24
Event History
Aug 27, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation over the network.
2
What is the potential impact?
The available severity vector indicates integrity impact only: an attacker may be able to modify data or application state. No confidentiality disclosure or availability impact is indicated.
3
Which installations should be prioritized for remediation?
WordPress sites using Kali Forms version 2.4.23 or earlier are identified as affected. Update to a version newer than 2.4.23 when one is available.