A vulnerability categorized as critical has been discovered in wpchill Kali Forms Plugin up to 2.4.20 on WordPress. The affected element is the function _save_data. Executing a manipulation of the argument thisPermalink can lead to code injection.

The identification of this vulnerability is CVE-2026-16144. The attack may be launched remotely. There is no exploit available.