Junglewise Threat Intelligence

CVE-2026-11581: Kali Forms WordPress plugin Stored XSS in form field captions

CVE-2026-11581 · Severity: info · CVSS 5.9 · Published 2026-06-30

Technologies: Kali Forms. Vendors: Kali Forms.

Executive brief

A security vulnerability exists in the Kali Forms WordPress plugin, which is used to create contact forms and manage user submissions. Users with low-level 'Contributor' access can inject malicious scripts into form field captions. When a site administrator views the form entries, these scripts execute in their browser, potentially allowing the attacker to perform administrative actions or take over the site.

Technical details

The Kali Forms plugin fails to sanitize form field captions before displaying them as column headers on the administrator's form-entries screen. While Contributors are normally restricted from publishing forms, a missing capability check in the 'kaliforms_duplicate_post' AJAX action allows them to bypass this restriction and publish a malicious draft. An attacker can use the WordPress REST API to inject a payload into the 'kaliforms_field_components' meta field and then use the duplication flaw to ensure the form is rendered for an administrator. This results in Stored XSS (CWE-79) that can be used for privilege escalation, such as creating a new administrator account via the wp.apiFetch API.

Affected products

  • Kali Forms Kali Forms — Contact Form & Drag-and-Drop Builder < 2.4.13

Timeline

  • 2026-06-09: disclosed: Initial public disclosure by WPScan
  • 2026-06-30: advisory: NVD publication date

References

Related threats