Answer in brief
CVE-2026-11580 records a Medium severity (CVSS 5.5) vulnerability in Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR. The current sources do not mark it as known exploited. The current feed maps Unknown/Kali Forms — Contact Form & Drag-and-Drop Builder (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/Kali Forms — Contact Form & Drag-and-Drop Builder (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric | >=0 <2.4.17 | 2.4.17 |
Published upstream
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-11580 records a Medium severity (CVSS 5.5) vulnerability in Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR. The current sources do not mark it as known exploited. The current feed maps Unknown/Kali Forms — Contact Form & Drag-and-Drop Builder (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Unknown/Kali Forms — Contact Form & Drag-and-Drop Builder (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Unknown/Kali Forms — Contact Form & Drag-and-Drop Buildergeneric | >=0 <2.4.17 | 2.4.17 |
Published upstream
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 15, 2026
The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-duplication AJAX action, allowing users with Contributor-level access or above to duplicate any post (regardless of owner, post type, or status) into a published post they own and read its private post metadata, including secrets stored by other Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17.
Quoted source text, attributed separately from HOL analysis.