Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.25 - Authenticated (Author+) Stored Cross-Site Scripting via Button 'clickAction' Field Property
- ID
- WPSEC-2026-0641
- Plugin
- Kali Forms — Contact Form & Drag-and-Drop Builder (kali-forms)
- Affected
- from 2.0.0 before 2.4.26
- Remediation
- Update to 2.4.26 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
- Attack surface
- Kali Forms — Contact Form & Drag-and-Drop Builder on WPSec AttackSurface
- Fix released
- Published
Description
The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button field's 'Function to run on click' (clickAction) property in versions 2.0.0 up to, and including, 2.4.25. The value is saved without checking for the unfiltered_html capability and is placed into the button's onclick attribute on the front end. The plugin applies only text sanitization and attribute escaping, which do not neutralize JavaScript in an event-handler attribute. This makes it possible for authenticated attackers with Author-level access and above, who can create and publish forms, to inject arbitrary JavaScript that executes when a user clicks the button on a page containing the form.
References
- https://wpsec.com/vuln/WPSEC-2026-0641/
- https://plugins.svn.wordpress.org/kali-forms/tags/2.4.26/
- https://wordpress.org/plugins/kali-forms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS