CVE-2026-11579: CWE-434 Unrestricted Upload of File with Dangerous Type in Kali Forms — Contact Form & Drag-and-Drop Builder
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.
AI Analysis
Technical Summary
The vulnerability in Kali Forms — Contact Form & Drag-and-Drop Builder prior to version 2.4.17 arises because the plugin does not verify that a file upload request corresponds to an existing form configured with a file-upload field. As a result, unauthenticated attackers can upload files directly to the WordPress Media Library. However, the plugin restricts uploads to MIME types allowed by WordPress by default, which mitigates the risk of remote code execution through this vector.
Potential Impact
Unauthenticated users can upload files to the WordPress Media Library, potentially leading to unauthorized content being hosted on the site. Since uploads are limited to default allowed MIME types, this does not enable direct code execution or immediate compromise of the site. The impact is primarily related to unauthorized file uploads and possible misuse of storage or content.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict file upload permissions and monitor uploads for unauthorized content. Avoid relying solely on MIME type restrictions for security.
CVE-2026-11579: CWE-434 Unrestricted Upload of File with Dangerous Type in Kali Forms — Contact Form & Drag-and-Drop Builder
Description
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.
CVSS v3.1
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Kali Forms — Contact Form & Drag-and-Drop Builder prior to version 2.4.17 arises because the plugin does not verify that a file upload request corresponds to an existing form configured with a file-upload field. As a result, unauthenticated attackers can upload files directly to the WordPress Media Library. However, the plugin restricts uploads to MIME types allowed by WordPress by default, which mitigates the risk of remote code execution through this vector.
Potential Impact
Unauthenticated users can upload files to the WordPress Media Library, potentially leading to unauthorized content being hosted on the site. Since uploads are limited to default allowed MIME types, this does not enable direct code execution or immediate compromise of the site. The impact is primarily related to unauthorized file uploads and possible misuse of storage or content.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict file upload permissions and monitor uploads for unauthorized content. Avoid relying solely on MIME type restrictions for security.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-06-08T11:45:18.284Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5722d468715ace43329157
Added to database: 07/15/2026, 06:04:04 UTC
Last enriched: 07/15/2026, 06:17:38 UTC
Last updated: 08/18/2026, 10:54:21 UTC
Views: 79
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.