logo

Hackers Actively Exploiting 9.8 Critical RCE Flaw in Kali Forms WordPress Plugin

ID: b2fde910-c7c6-53c0-83d3-3c4569543950

STIX ID: report--b2fde910-c7c6-53c0-83d3-3c4569543950

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-26

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical unauthenticated RCE vulnerability (CVE-2026-3584, CVSS 9.8) in the Kali Forms WordPress plugin (≤2.4.9) is being actively exploited — Wordfence blocked 2,370 attacks in 24 hours. Site owners should immediately update to version 2.4.10 or later to prevent full site takeover, data theft, or persistent malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.