Hackers Actively Exploiting 9.8 Critical RCE Flaw in Kali Forms WordPress Plugin
ID: b2fde910-c7c6-53c0-83d3-3c4569543950
STIX ID: report--b2fde910-c7c6-53c0-83d3-3c4569543950
Feed Name: securityonline.info
Threat Score
A critical unauthenticated RCE vulnerability (CVE-2026-3584, CVSS 9.8) in the Kali Forms WordPress plugin (≤2.4.9) is being actively exploited — Wordfence blocked 2,370 attacks in 24 hours. Site owners should immediately update to version 2.4.10 or later to prevent full site takeover, data theft, or persistent malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
