All verified exploits

CVE-2026-3584 Kali Forms Remote Code Execution

Deterministic critical WordPress Added cve-verified-cve-2026-3584

Detects the Kali Forms WordPress plugin before version 2.4.10, where the form processor maps user-supplied POST keys into internal placeholder storage. Placeholders like {entryCounter} and {thisPermalink} are later passed to call_user_func(), allowing unauthenticated attackers to execute arbitrary PHP functions.

Related WordPress exploits

Is your app exploitable through CVE-2026-3584?

Scan your domain free