Skip to content

Known CVE

WordPress Kali Forms <= 2.4.9 - Remote Code Execution

Kali Forms WordPress plugin <= 2.4.9 contains a remote code execution caused by unsafe user input handling in 'form_process' and 'prepare_post_data' functions, letting unauthenticated attackers execute code on the server, exploit requires no authentication.

CVE-2026-3584

Critical2026CVSS 9.8CWE-94

cve2026 · wordpress · wp-plugin · kali-forms · rce · unauth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website