The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 20 Mar 2026 21:30:00 +0000

Type Values Removed Values Added
Description The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server.
Title Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-03-20T21:25:11.166Z

Reserved: 2026-03-05T05:20:57.880Z

Link: CVE-2026-3584

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-20T22:16:29.267

Modified: 2026-03-20T22:16:29.267

Link: CVE-2026-3584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses