CVE-2026-11581

MEDIUM

Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-11581. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-11581, a reflected XSS vulnerability in the Kali Forms WordPress plugin (versions before 2.4.13). The module includes placeholder code with no functional exploit implementation, only basic connectivity checks and TODO warnings.

Description

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as a column header on the administrator form-entries screen, allowing users with Contributor-level access or above to store JavaScript that executes in an administrator's session. A missing capability check in the Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13's post-duplication action additionally lets the Contributor publish the malicious form so an administrator renders it.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-11581_the_kali_forms.py

This repository contains an auto-generated stub module for CVE-2026-11581, a reflected XSS vulnerability in the Kali Forms WordPress plugin (versions before 2.4.13). The module includes placeholder code with no functional exploit implementation, only basic connectivity checks and TODO warnings.

Classification
Stub 99%
Attack Type
Xss
Complexity
Moderate
Reliability
Theoretical
Target: Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13
Auth required
Prerequisites: WordPress site with vulnerable Kali Forms plugin installed · Administrator access to view form entries (XSS triggers in admin panel)
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/a9282260-a0f2-4fe2-9acf-3191f4043910/

Scores

CVSS v3 5.9
EPSS 0.0014
EPSS Percentile 3.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

Status published
Products (1)
None/Kali Forms — Contact Form & Drag-and-Drop Builder < 2.4.13
Published Jun 30, 2026
Tracked Since Jun 30, 2026