Known CVE
WordPress Kali Forms <= 2.4.9 - Remote Code Execution
Kali Forms WordPress plugin <= 2.4.9 contains a remote code execution caused by unsafe user input handling in 'form_process' and 'prepare_post_data' functions, letting unauthenticated attackers execute code on the server, exploit requires no authentication.
CVE-2026-3584
Critical2026CVSS 9.8CWE-94
cve2026 · wordpress · wp-plugin · kali-forms · rce · unauth · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website