kokumօtօ[verified]@__kokumotoActive Exploitation
CVE-2026-3584, a critical vulnerability in Kali Forms, is actively exploited allowing arbitrary code execution via malicious form submissions; a patch is available in version 2.4.10.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE-2026-3584, a critical RCE in Kali Forms, has been actively exploited since its March 20, 2026 patch disclosure, with attackers using function injection to bypass authentication, elevate to admin, and deploy malware through theme files.
SwissWPSecure[verified]@SwisswpsecureActive Exploitation
The tweet alerts that CVE-2026-3584 and CVE-2026-0740 are being actively exploited with massive attack volume, provides patch versions, and urges admins to update and harden sites.
セキュリティ対策Lab[verified]@securityLab_jpDisclosure
A blog post announces a serious unauthenticated RCE vulnerability (CVE-2026-3584) in the WordPress Kali Forms plugin, providing the CVE ID and vulnerability type but no PoC, exploit code, patch, or exploitation evidence.
Orizon[verified]@OrizonCyberPatch
The post alerts that CVE‑2026‑3584 is a critical Remote Code Execution flaw in the Kali Forms WordPress plugin and that a patch is already available.
N Shams[verified]@Nav_the_ShamDisclosure
The post discloses CVE-2026-3584, a high‑severity RCE flaw in Kali Forms plugin for WordPress, detailing how a malicious key invokes call_user_func to execute unauthorized code, but does not mention a PoC, active exploitation, or available patch.
Gray Hats@the_yellow_fallActive Exploitation
The post reports that CVE‑2026‑3584 is currently being exploited, offers a patch update, and provides basic vulnerability details.
pdnuclei-bot@pdnuclei_botDisclosure
The tweet announces a newly disclosed critical RCE vulnerability in the Kali Forms WordPress plugin (≤2.4.9) and provides a link for more details, but includes no PoC, exploit code, or patch information.