Kali Forms
cpe:2.3:a:kaliforms:kali_forms:*:*:*:*:wordpress:*:*
- <= 2.4.9
A remote code execution vulnerability exists in the Kali Forms plugin for WordPress, affecting all versions through 2.4.9. The issue arises in the 'form_process' function, where user-supplied keys are directly mapped into internal placeholder storage. This, combined with the use of 'call_user_func' on these placeholder values, allows unauthenticated attackers to execute arbitrary code on the server.
Exploitation of this vulnerability allows for unauthenticated remote code execution on the server where the affected WordPress site is hosted.
To reproduce this vulnerability, send a request to the WordPress site with the 'form_process' action. Include crafted submission data that exploits the 'prepare_post_data' function by overwriting internal placeholders with keys that match real form fields. This will trigger the execution of arbitrary code via the manipulated placeholders.
Users are advised to update the Kali Forms plugin to version 2.4.10 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.