CVE-2026-16144
Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter
Record summary
CVE-2026-16144 has a selected CVSS score of 8.1 (high).
Description
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callable placeholder, allowing attacker-controlled strings to reach call_user_func() in _save_data(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires the target form to define a field with a name matching one of the reserved placeholder keys ('thisPermalink', 'entryCounter', or 'submission_link'), as check_if_placeholders_changed() only processes POST keys present in the form's field_type_map.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 5, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
contact_form_builderBrowse kaliforms / contact_form_builder | VulnCheck | Version data not supplied | |
Kali Forms — Contact Form & Drag-and-Drop BuilderBrowse wpchill / Kali Forms — Contact Form & Drag-and-Drop BuilderDefault status: unaffected | CVE List | Through 2.4.20 | affected |