CVE-2025-3201

Kali Forms < 2.4.3 - Contributor+ Stored XSS

The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.


We have discovered 1,983 live websites that are affected by CVE-2025-3201.

Run a Free Instant Scan




Affected Software

Product  Kali Forms
Category Wordpress Plugins
Vulnerable Domains1,983 live websites (38% of Kali Forms install base)
Vulnerable Versions
  • from 0 through 2.4.3
Vulnerable Versions Count76 versions ( 89% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - May 16, 2025
  • Updated - May 16, 2025

Credits

  • Dmitrii Ignatyev (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-3201
United States445 websites



Germany267 websites
France164 websites
Netherlands96 websites
GB77 websites
Poland77 websites
Italy75 websites
Spain58 websites
Russia48 websites
Czech Republic48 websites

Website Distribution by TLD

Number of websites using CVE-2025-3201
.com710 websites
.de156 websites
.org103 websites
.nl94 websites
.fr61 websites
.pl54 websites
.co.uk52 websites
.it48 websites
.net47 websites
.cz45 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-3201

Top websites that are affected by CVE-2025-3201. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.com Italy***,***
************.com United States***,***
***************.cz Czech Republic***,***
****.****.***.ph Philippines***,***
****************.com United States***,***
****************.com United States*,***,***
*********.de Germany*,***,***
************.it Italy*,***,***
**********.com United States*,***,***
**.******.de Germany*,***,***
See full domain list

FAQ

CVE-2025-3201 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Kali Forms
A total of 1,983 websites have been identified as vulnerable to CVE-2025-3201, based on global website indexing conducted by WebTechSurvey.
The Kali Forms is affected by the CVE-2025-3201 vulnerability.
Kali Forms versions up to 2.4.3 are vulnerable to CVE-2025-3201.
CVE-2025-3201 is resolved in version 2.4.3 of Kali Forms.