Junglewise Threat Intelligence

CVE-2026-11580: Kali Forms WordPress plugin IDOR in post-duplication AJAX action

CVE-2026-11580 · Severity: info · CVSS 5.5 · Published 2026-07-15

Technologies: Kali Forms. Vendors: Kali Forms.

Executive brief

Kali Forms, a popular WordPress plugin for building contact forms, contains a security flaw that allows low-privileged users (like Contributors) to access private information. By exploiting this, an attacker can duplicate any post or page on the site—even those they shouldn't see—and read sensitive metadata, such as private notes or secret API keys. This could lead to the exposure of confidential business data or credentials used by other site components.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) within the 'kaliforms_duplicate_post' AJAX action. The plugin does not perform a per-object capability check to verify if the requesting user has permission to access the source post being duplicated. An authenticated attacker with Contributor-level access or higher can provide an arbitrary post ID to the AJAX action, which then creates a published duplicate of that post under the attacker's ownership. This process copies all associated post metadata, allowing the attacker to read private custom fields and secrets (such as API keys) belonging to other users or plugins. The issue is fixed in version 2.4.17.

Affected products

  • Kali Forms Kali Forms — Contact Form & Drag-and-Drop Builder < 2.4.17

Timeline

  • 2026-06-24: disclosed: Publicly published by WPScan
  • 2026-07-15: advisory: NVD publication date
  • 2026-07-15: patched: Fixed in version 2.4.17

References

Related threats