Stored Cross-Site Scripting Vulnerability in Kali Forms Plugin for WordPress
CVE-2026-15395
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 July 2026
What is CVE-2026-15395?
The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting through the 'digitalSignature' field. This vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject malicious scripts that execute in the browser of any user accessing the affected forms. The nonce used for form submission is publicly accessible on pages with the form shortcode, providing an easy entry point for attackers to exploit, even without prior authentication. Users are strongly advised to update to the latest plugin version to mitigate this risk.
Affected Version(s)
Kali Forms β Contact Form & Drag-and-Drop Builder 0 <= 2.4.18