Answer in brief
CVE-2026-11579 records a Medium severity (CVSS 5.3) vulnerability in Kali Forms < 2.4.17 - Unauthenticated Media Upload. The current sources do not mark it as known exploited. The current feed maps Unknown/Kali Forms — Contact Form & Drag-and-Drop Builder (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/Kali Forms — Contact Form & Drag-and-Drop Builder (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric | >=0 <2.4.17 | 2.4.17 |
Published upstream
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-11579 records a Medium severity (CVSS 5.3) vulnerability in Kali Forms < 2.4.17 - Unauthenticated Media Upload. The current sources do not mark it as known exploited. The current feed maps Unknown/Kali Forms — Contact Form & Drag-and-Drop Builder (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/Kali Forms — Contact Form & Drag-and-Drop Builder (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric | >=0 <2.4.17 | 2.4.17 |
Published upstream
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing form configured with a file-upload field, accepting uploads regardless of whether any such form exists, which allows unauthenticated users to upload files to the WordPress Media Library; the uploads are limited to WordPress's default-allowed MIME types, so this does not lead to code execution.
Quoted source text, attributed separately from HOL analysis.