S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Apr 9, 2026

CVE-2026-3584 Scanner

CVE-2026-3584 Scanner - Remote Code Execution (RCE) vulnerability in Kali Forms WordPress plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-3584
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Kali Forms — Contact Form & Drag-and-Drop Builderby wpchill
0
Updated Aug 22, 2026View on NVD →
Detail

Kali Forms is a popular WordPress plugin used for form creation and management on WordPress sites. It is widely utilized by website administrators and developers to facilitate user input through customizable forms. The plugin offers a variety of form templates, supporting functionalities such as contact forms, feedback forms, and surveys. Its ease of use and flexibility make it an attractive choice for users looking to add forms to their WordPress sites without extensive coding knowledge. However, as with any software component that handles user input, it's crucial to ensure secure handling to prevent potential exploits. Regular updates and security reviews are recommended to maintain a secure environment.

This scanner detects a critical Remote Code Execution (RCE) vulnerability in the Kali Forms WordPress plugin. This vulnerability arises from improper handling of user inputs in certain functions, which could allow attackers to execute arbitrary code on the server. It's classified as being highly severe due to its potential to compromise affected systems entirely. The exploitation of this vulnerability does not require authentication, which further increases its risk profile. Consequently, it's crucial for users of affected versions to address this security issue promptly.

The technical details reveal that the vulnerability resides in the 'form_process' and 'prepare_post_data' functions of the plugin. These functions insufficiently sanitize user input, creating an opportunity for attackers to inject and execute code on the server. The scanner checks various endpoints such as '/contact-us/', '/contact/', '/form/', '/feedback/' to verify if the system is vulnerable. It extracts information like the nonce and form ID to perform a POST request that demonstrates the vulnerability by successfully executing 'phpinfo()', indicating potential code execution.

If exploited, this vulnerability could lead to severe consequences, including a full system compromise. Malicious actors could gain unauthorized access, execute arbitrary commands, and potentially take control of the affected server. This might result in the exposure of sensitive data, disruption of service, and could be leveraged to launch further attacks. It emphasizes the importance of swiftly updating to a secure version and reinforcing security practices associated with handling inputs.

REFERENCES

Solution Advice
  • Update Kali Forms to a version beyond 2.4.9 to mitigate the Remote Code Execution vulnerability.
  • Regularly monitor and promptly apply security patches for installed plugins to minimize exposure to known vulnerabilities.
  • Implement input validation and sanitization techniques to further reduce the risk of code injection attacks.
  • Conduct periodic security assessments and audits on your WordPress site to catch and address vulnerabilities early.
  • Harden the underlying hosting environment by restricting unnecessary access to sensitive server functionalities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.