# Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.25 - Authenticated (Author+) Stored Cross-Site Scripting via Button 'clickAction' Field Property

- **ID:** WPSEC-2026-0641
- **Plugin:** Kali Forms — Contact Form & Drag-and-Drop Builder (`kali-forms`), https://wordpress.org/plugins/kali-forms/
- **Affected versions:** from 2.0.0 before 2.4.26
- **Fixed in:** 2.4.26 (Update to 2.4.26 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/kali-forms
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0641/

## Description

The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button field's 'Function to run on click' (clickAction) property in versions 2.0.0 up to, and including, 2.4.25. The value is saved without checking for the unfiltered_html capability and is placed into the button's onclick attribute on the front end. The plugin applies only text sanitization and attribute escaping, which do not neutralize JavaScript in an event-handler attribute. This makes it possible for authenticated attackers with Author-level access and above, who can create and publish forms, to inject arbitrary JavaScript that executes when a user clicks the button on a page containing the form.

## References

- https://wpsec.com/vuln/WPSEC-2026-0641/
- https://plugins.svn.wordpress.org/kali-forms/tags/2.4.26/
- https://wordpress.org/plugins/kali-forms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0641/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
