CVE-2026-16144 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This makes it possible for unauthenticated attackers to execute code
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires the target form to define a field with a name matching one of the reserved placeholder keys ('thisPermalink', 'entryCounter', or 'submission_link'), as check_if_placeholders_changed() only processes POST keys present in the form's field_type_map.
- 🔗 www.wordfence.com/threat-intel/vulnerabilities/id/9d692aff-…
- 🔗 plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Fronte…
- 🔗 plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Fronte…
- 🔗 plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Fronte…
- 🔗 plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Fronte…
- 🔗 plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.20/Inc/Fronte…
- 🔗 plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.19/Inc/Fronte…
- 🔗 plugins.trac.wordpress.org/browser/kali-forms/tags/2.4.19/Inc/Fronte…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-14 | 2026-09-27 |
|---|---|---|
| ≥90 % | 0 | 497 |
| ≥50 % | 0 | 1468 |
| ≥10 % | 0 | 4 |
| <10 % | 300 | 297 |
CVE-2026-16144 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This makes it possible for unauthenticated attackers to execute code
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisP
Noch keine Analyse zu CVE-2026-16144
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.