Unrated severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
CVE-2026-11580
Description
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/d73500e1-a8bc-4d31-ad9b-d1f71212bcc7/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.