{
 "id": "WPSEC-2026-0641",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0641/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0641/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0641/index.md",
 "title": "Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.25 - Authenticated (Author+) Stored Cross-Site Scripting via Button 'clickAction' Field Property",
 "description": "The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button field's 'Function to run on click' (clickAction) property in versions 2.0.0 up to, and including, 2.4.25. The value is saved without checking for the unfiltered_html capability and is placed into the button's onclick attribute on the front end. The plugin applies only text sanitization and attribute escaping, which do not neutralize JavaScript in an event-handler attribute. This makes it possible for authenticated attackers with Author-level access and above, who can create and publish forms, to inject arbitrary JavaScript that executes when a user clicks the button on a page containing the form.",
 "plugin": {
  "slug": "kali-forms",
  "name": "Kali Forms — Contact Form & Drag-and-Drop Builder",
  "full_name": "Kali Forms — Contact Form & Drag-and-Drop Builder",
  "wordpress_org": "https://wordpress.org/plugins/kali-forms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/kali-forms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/kali-forms"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.0.0",
    "from_inclusive": true,
    "to": "2.4.26",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.0.0 before 2.4.26"
  ]
 },
 "introduced_in": "2.0.0",
 "fixed_in": "2.4.26",
 "remediation": "Update to 2.4.26 or later.",
 "fix_released": "2026-10-07T10:43:34+00:00",
 "published": "2026-10-08T10:46:37+00:00",
 "updated": "2026-10-07T14:56:11.481749+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0641/",
  "https://plugins.svn.wordpress.org/kali-forms/tags/2.4.26/",
  "https://wordpress.org/plugins/kali-forms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/kali-forms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}