Kali Forms WordPress Plugin Post Duplication Vulnerability Allowing Arbitrary Private Metadata Disclosure

Vulnerability

A vulnerability exists in the Kali Forms WordPress plugin, specifically in versions prior to 2.4.17. The issue arises because the plugin's post-duplication AJAX action fails to implement a per-object capability check. This flaw enables users with Contributor-level access or higher to duplicate any post, regardless of the owner's identity, post type, or status, into a published post they control. Additionally, this vulnerability allows access to private post metadata, including sensitive information stored by other plugins.

Impact

Exploitation of this vulnerability allows unauthorized users to access and disclose private metadata from posts owned by other users, including sensitive information such as API keys and private notes.

Reproduction

To reproduce this vulnerability, log in as a Contributor user and obtain a session-bound nonce. This nonce can be accessed on any front-end page containing a Kali form or through the 'get_js_var' AJAX action. Once the nonce is obtained, duplicate a private post owned by an administrator by sending a request to the 'admin-ajax.php' endpoint with the post ID, the user ID of the Contributor, and the nonce. The duplicated post will be created under the Contributor's account, with all private metadata from the original post copied over.

Remediation

Users are advised to update the Kali Forms WordPress plugin to version 2.4.17 or later.

Added: Jul 15, 2026, 7:21 AM
Updated: Jul 15, 2026, 7:21 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
3.1
exploitability
6.8
remediation
7.7
relevance
9.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.