Hackers Exploit Kali Forms Vulnerability to Take Over WordPress Sites
ID: e3d97b29-55fa-5602-ad6f-c1493b9f032c
STIX ID: report--e3d97b29-55fa-5602-ad6f-c1493b9f032c
Feed Name: The Cyber Express
A critical unauthenticated Remote Code Execution flaw in the Kali Forms WordPress plugin (<=2.4.9) was disclosed and patched on March 20, 2026, but immediately exploited in the wild—observers recorded over 312,200 exploit attempts and peak activity between April 4–10, 2026. The issue stems from unvalidated, attacker-controlled placeholder values passing into call_user_func, enabling attackers to run PHP functions (including wp_set_auth_cookie for potential account takeover) via automated POST requests to wp-admin/admin-ajax.php; several IPs were repeatedly observed performing large-scale exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
