PT-2026-26682 · Wpchill · Kali Forms — Contact Form & Drag-And-Drop Builder
Ismailshadow
·
Published
2026-03-20
·
Updated
2026-03-20
·
CVE-2026-3584
CVSS v3.1
9.8
Critical
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form process' function. This is due to the 'prepare post data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call user func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kali Forms — Contact Form & Drag-And-Drop Builder