PT-2026-26682 · Wpchill · Kali Forms — Contact Form & Drag-And-Drop Builder

Ismailshadow

·

Published

2026-03-20

·

Updated

2026-03-20

·

CVE-2026-3584

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form process' function. This is due to the 'prepare post data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call user func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-3584

Affected Products

Kali Forms — Contact Form & Drag-And-Drop Builder