{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/kali-forms--contact-form--drag-and-drop-builder--2.4.20/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-16144"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kali Forms — Contact Form \u0026 Drag-and-Drop Builder (\u003c= 2.4.20)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","wordpress","rce"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Kali Forms - Contact Form \u0026amp; Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution (RCE) in all versions up to and including 2.4.20. The vulnerability resides in the _save_data function, where improper input validation occurs on the 'thisPermalink' field. Specifically, the application fails to validate the value before it overwrites a trusted callable placeholder. An attacker can supply a crafted string that reaches the call_user_func() function within _save_data(). This allows an unauthenticated user to trigger arbitrary code execution on the server. Exploitation requires that a target form defines a field name matching one of the reserved placeholder keys: 'thisPermalink', 'entryCounter', or 'submission_link', as the check_if_placeholders_changed() function only processes POST keys present in the form's field_type_map. Organizations using this plugin should update to a patched version immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated attacker to execute arbitrary code on the underlying web server hosting the WordPress site. This can lead to full site compromise, data exfiltration, installation of web shells, and potential lateral movement into the hosting environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch the Kali Forms WordPress plugin to the latest available version that resolves CVE-2026-16144.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect POST requests directed at WordPress plugins, specifically flagging requests containing unexpected PHP function names or serialized objects in fields mapped to placeholder keys like 'thisPermalink'.\u003c/li\u003e\n\u003cli\u003eAudit the configuration of all active forms to ensure no fields are using reserved names that match the affected placeholder keys.\u003c/li\u003e\n\u003cli\u003eEnable server-side logging for web requests and monitor for anomalous execution patterns originating from WordPress plugin directories.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-01T09:50:14Z","date_published":"2026-08-01T09:50:14Z","id":"https://feed.craftedsignal.io/briefs/2026-08-kali-forms-rce/","summary":"Unauthenticated attackers can achieve remote code execution in Kali Forms versions up to 2.4.20 by exploiting insufficient validation of the thisPermalink field within the _save_data function.","title":"Remote Code Execution in Kali Forms WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-kali-forms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Kali Forms — Contact Form \u0026 Drag-and-Drop Builder (\u003c= 2.4.20)","version":"https://jsonfeed.org/version/1.1"}