Description
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires the target form to define a field with a name matching one of the reserved placeholder keys ('thisPermalink', 'entryCounter', or 'submission_link'), as check_if_placeholders_changed() only processes POST keys present in the form's field_type_map.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 01 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpchill Wpchill kali Forms — Contact Form & Drag-and-drop Builder |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpchill Wpchill kali Forms — Contact Form & Drag-and-drop Builder |
Sat, 01 Aug 2026 08:30:00 +0000
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-01T07:49:50.355Z
Reserved: 2026-07-17T17:45:06.586Z
Link: CVE-2026-16144
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-01T09:45:03Z
Weaknesses