Detects the Kali Forms WordPress plugin before version 2.4.10, where the form processor maps user-supplied POST keys into internal placeholder storage. Placeholders like {entryCounter} and {thisPermalink} are later passed to call_user_func(), allowing unauthenticated attackers to execute arbitrary PHP functions.
Is your app exploitable through CVE-2026-3584?
Scan your domain free