Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.25 - Authenticated (Author+) Stored Cross-Site Scripting via Button 'clickAction' Field Property

Medium 5.4 CWE-79Fixed in 2.4.26
ID
WPSEC-2026-0641
Plugin
Kali Forms — Contact Form & Drag-and-Drop Builder (kali-forms)
Affected
from 2.0.0 before 2.4.26
Remediation
Update to 2.4.26 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-08
Attack surface
Kali Forms — Contact Form & Drag-and-Drop Builder on WPSec AttackSurface
Fix released
Published

Description

The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button field's 'Function to run on click' (clickAction) property in versions 2.0.0 up to, and including, 2.4.25. The value is saved without checking for the unfiltered_html capability and is placed into the button's onclick attribute on the front end. The plugin applies only text sanitization and attribute escaping, which do not neutralize JavaScript in an event-handler attribute. This makes it possible for authenticated attackers with Author-level access and above, who can create and publish forms, to inject arbitrary JavaScript that executes when a user clicks the button on a page containing the form.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0