Stored Cross-Site Scripting Vulnerability in Kali Forms Plugin for WordPress
CVE-2026-15395

7.2HIGH

What is CVE-2026-15395?

The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting through the 'digitalSignature' field. This vulnerability arises from inadequate input sanitization and output escaping, allowing unauthenticated attackers to inject malicious scripts that execute in the browser of any user accessing the affected forms. The nonce used for form submission is publicly accessible on pages with the form shortcode, providing an easy entry point for attackers to exploit, even without prior authentication. Users are strongly advised to update to the latest plugin version to mitigate this risk.

Affected Version(s)

Kali Forms β€” Contact Form & Drag-and-Drop Builder 0 <= 2.4.18

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PRISM
.