Report: CVE-2026-3584 - Kali Forms <= 2.4.9 - unauthenticated remote code execution via form_process

Report: CVE-2026-3584 - Kali Forms <= 2.4.9 - unauthenticated remote code execution via form_process

CVE ID :CVE-2026-3584 Published : March 20, 2026, 9:25 p.m. | 59 minutes ago Description :The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
March 20, 2026
Affected Product: WordPress
Impact: Remote Code Execution