CVE-2026-11580

Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.


We have discovered 1,847 live websites that are affected by CVE-2026-11580.

Run a Free Instant Scan




Affected Software

Product  Kali Forms
Category Wordpress Plugins
Vulnerable Domains1,847 live websites (94% of Kali Forms install base)
Vulnerable Versions
  • from 0 through 2.4.17
Vulnerable Versions Count72 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Jul 15, 2026
  • Updated - Jul 15, 2026

Credits

  • Muni Nitish Kumar Yaddala (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-11580
United States503 websites



Germany263 websites
Netherlands147 websites
GB128 websites
France119 websites
Italy64 websites
Poland52 websites
Czech Republic44 websites
Australia35 websites
Spain34 websites

Website Distribution by TLD

Number of websites using CVE-2026-11580
.com690 websites
.de162 websites
.nl132 websites
.org91 websites
.co.uk84 websites
.fr65 websites
.net43 websites
.cz40 websites
.it34 websites
.pl34 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-11580

Top websites that are affected by CVE-2026-11580. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.com Italy***,***
***************.cz Czech Republic***,***
*****.eu United States***,***
*****************.nl Netherlands***,***
****************.com GB***,***
**.*****.com GB*,***,***
****************.com United States*,***,***
*********.ru Russia*,***,***
**********.**.za South Africa*,***,***
**************.com United States*,***,***
See full domain list

FAQ

CVE-2026-11580 is Authorization Bypass Through User-Controlled Key in Kali Forms
A total of 1,847 websites have been identified as vulnerable to CVE-2026-11580, based on global website indexing conducted by WebTechSurvey.
The Kali Forms is affected by the CVE-2026-11580 vulnerability.
Kali Forms versions up to 2.4.17 are vulnerable to CVE-2026-11580.
CVE-2026-11580 is resolved in version 2.4.17 of Kali Forms.