TopVuln

High-risk vulnerability digests

CVE-2026-3584

  • CRITICAL

Exploit for CVE-2026-3584

Details

CVSS v3
9.8
NVD published
2026-03-20 22:16:29
EPSS
0.2% probability · 44.2th percentile — 2026-03-24
Affected versions
Not available in our cache.
Summary
The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server.
Remediation
Not available in our cache.
Exploit info
Not available in our cache.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.