CVE-2026-11581 Details
Description
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's session. A missing capability check in the Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13's post-duplication action additionally lets the Contributor publish the malicious form so an administrator renders it.
A stored cross-site scripting vulnerability has been identified in the Kali Forms WordPress plugin, specifically in versions prior to 2.4.13. The issue arises because the plugin fails to properly sanitize form field captions before displaying them as column headers on the administrator form entries screen. This oversight allows users with Contributor-level access or higher to inject JavaScript that executes in the context of an administrator's session. Additionally, a missing capability check in the plugin's post-duplication action enables Contributors to publish the malicious forms, further exposing administrators to the risk.
Users are advised to update the Kali Forms WordPress plugin to version 2.4.13 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/a9282260-a0f2-4fe2-9acf-3191f4043910/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Kali Forms | < 2.4.13 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion