The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server.
We have discovered 4,908 live websites that are affected by CVE-2026-3584.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 4,908 live websites (94% of Kali Forms install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 83 versions ( 98% of all versions) |
| 1,327 websites | |
| 746 websites | |
| 369 websites | |
| 279 websites | |
| 242 websites | |
| 171 websites | |
| 145 websites | |
| 109 websites | |
| 105 websites | |
| 101 websites |
| .com | 1,860 websites |
| .de | 475 websites |
| .org | 268 websites |
| .nl | 264 websites |
| .fr | 154 websites |
| .co.uk | 154 websites |
| .net | 125 websites |
| .it | 110 websites |
| .pl | 103 websites |
| .ch | 84 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.io | ***,*** | ||
| ***************.com | ***,*** | ||
| ***********.me | ***,*** | ||
| ************.com | ***,*** | ||
| ***************.cz | ***,*** | ||
| *****.eu | ***,*** | ||
| ****.****.***.ph | ***,*** | ||
| ****************.de | ***,*** | ||
| **************.com | ***,*** | ||
| *********.it | ***,*** |
FAQ