CVE-2026-3584Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_data' function mapping user-supplied keys directly into internal placeholder storage, combined with the use of 'call_user_func' on these placeholder values. This makes it possible for unauthenticated attackers to execute code on the server.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 8 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 13 signals
  • Disclosure: 6 classified signals
  • Peaked 7d ago at 4 mentions (2026-03-20); latest day: 1
  • 13 total mentions across 8 days

Deep dive

Activity timeline13 mentions / 8d
01234Mentions · 2026-03-20: 4Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Mentions · 2026-03-26: 3Mentions · 2026-03-31: 1Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-03-20: 1Exploit Tool / Code · 2026-04-14: 1Active Exploitation · 2026-03-26: 3Active Exploitation · 2026-04-10: 1Active Exploitation · 2026-04-14: 1Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-26: 3Technical Details · 2026-03-31: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-14: 103-2003-2103-2203-2603-3104-0904-1004-14
Signal classification3 categories
Disclosure
646.2%
Active Exploitation
538.5%
Patch
215.4%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-204
Disclosure2Patch2
2026-03-211
Disclosure1
2026-03-221
Disclosure1
2026-03-263
Active Exploitation3
2026-03-311
Disclosure1
2026-04-091
Disclosure1
2026-04-101
Active Exploitation1
2026-04-141
Active Exploitation1
Full discourse13 posts
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Hackers are actively exploiting a 9.8 CVSS RCE flaw in Kali Forms (CVE-2026-3584). Over 10,000 WordPress sites are at risk. Update to version 2.4.10 now! #WordPress #CyberSecurity #KaliForms #RCE #InfoSec #WebSecurity #Vulnerability #Wordfence #PatchNow https://securityonline.info/kali-forms-vulnerability-wordpress-rce-cve-2026-3584/ https://t.co/pC3uVqzXel

    Post summary

    The post reports that CVE‑2026‑3584 is currently being exploited, offers a patch update, and provides basic vulnerability details.

    16095911
    10.9K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-3584 - critical 🚨 WordPress Kali Forms <= 2.4.9 - Remote Code Execution > Kali Forms WordPress plugin <= 2.4.9 contains a remote code execution caused by unsaf... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-3584 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a newly disclosed critical RCE vulnerability in the Kali Forms WordPress plugin (≤2.4.9) and provides a link for more details, but includes no PoC, exploit code, or patch information.

    00014183
    916 followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    1万サイト以上が使用するWordPressのKali Formsにおける重大(Critical)な脆弱性が悪用されている。CVE-2026-3584はCVSSスコア9.8で、悪意あるフォーム送信からの任意コード実行が可能。バージョン2.4.10で修正。 https://securityonline.info/kali-forms-vulnerability-wordpress-rce-cve-2026-3584/

    Post summary

    CVE-2026-3584, a critical vulnerability in Kali Forms, is actively exploited allowing arbitrary code execution via malicious form submissions; a patch is available in version 2.4.10.

    010311.1K
    7.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Critical RCE in Kali Forms WordPress plugin actively exploited since patch disclosure. Attackers bypass authentication via function injection, escalate to admin access, then deploy malware through theme files. Key technical details: • CVE-2026-3584 (CVSS 9.8) affects Kali Forms ≤2.4.9, patched in v2.4.10 • Vulnerability in prepare_post_data() function allows overwriting placeholders like {entryCounter} • Exploitation via call_user_func() enables execution of wp_set_auth_cookie(1) for admin bypass • POST to /wp-admin/admin-ajax.php with action=kaliforms_form_process and crafted entryCounter parameter Attack progression: • Mass exploitation began March 20, 2026 (disclosure day) with 312K+ blocked attempts • Peak activity April 4-10 coinciding with free Wordfence protection rollout • Top attacking IPs: 209[.]146[.]60[.]26 (152K attempts), 49[.]156[.]40[.]126 (50K attempts) • Post-compromise: attackers edit functions.php to inject persistent malware Hunt for POST requests to admin-ajax.php containing "kaliforms_form_process" action with suspicious entryCounter values. Review admin login logs for unusual authentication around March 20-April 10 timeframe. #DFIR_Radar

    Post summary

    CVE-2026-3584, a critical RCE in Kali Forms, has been actively exploited since its March 20, 2026 patch disclosure, with attackers using function injection to bypass authentication, elevate to admin, and deploy malware through theme files.

    10012336
    1.7K followersView on X
  • SwissWPSecure@Swisswpsecure
    Active Exploitation

    1/ WP Sec Brief Apr 10 — Quiet 48h from Wordfence/WPScan/Sucuri/WP.org. But two active CVSS 9.8 RCEs are wrecking sites right now. Thread 🧵 #WordPressSecurity 2/ CVE-2026-3584 — Kali Forms ≤ 2.4.9. No login needed. Submit a form with a PHP function name → server executes it. Full admin takeover in one request. Exploitation surged 64× in 7 days: 438 → 10,600+ attempts. Patch to 2.4.10 NOW. 3/ CVE-2026-0740 — Ninja Forms File Uploads ≤ 3.3.26. Unauthenticated AJAX file upload → RCE. ~50,000 sites exposed. CVSS 9.8. Patch to 3.3.27. 4/ SwissWPSuite v2.9.27.61 blocks both: WAF stops PHP execution in uploads, Sentinel scans webshell filenames + malware signatures, IP banning shuts down attack sweeps. No downtime, no guesswork. 5/ Quiet days = audit time. Check admin accounts. Scan your install. Harden /uploads. Don't wait for the breach to act. https://swisswpsecure.com/%f0%9f%9a%a8-wordpress-security-brief-april-10-2026-no-new-disclosures-but-kali-forms-is-under-siege/ #WordPress #RCE #CyberSec #SwissWPSuite

    Post summary

    The tweet alerts that CVE-2026-3584 and CVE-2026-0740 are being actively exploited with massive attack volume, provides patch versions, and urges admins to update and harden sites.

    0001032
    1 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    WordPressのフォーム プラグイン Kali Formsに深刻な認証不要 RCE 脆弱性(CVE-2026-3584) https://rocket-boys.co.jp/security-measures-lab/wordpress-kali-forms-unauth-rce-cve-2026-3584/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    A blog post announces a serious unauthenticated RCE vulnerability (CVE-2026-3584) in the WordPress Kali Forms plugin, providing the CVE ID and vulnerability type but no PoC, exploit code, patch, or exploitation evidence.

    00001119
    363 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3584 The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to t… https://www.cve.org/CVERecord?id=CVE-2026-3584

    Post summary

    CVE-2026-3584 targets the Kali Forms WordPress plugin, allowing remote code execution through the form_process function in versions up to 2.4.9. No PoC, exploit, or patch details are mentioned.

    00001156
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-3584: CRITICAL] Warning: Vulnerability in Kali Forms plugin for WordPress allows Remote Code Execution up to version 2.4.9 via 'form_process' function. Ensure immediate security patch.#cve,CVE-2026-3584,#cybersecurity https://cvefind.com/CVE-2026-3584

    Post summary

    The tweet warns of a critical RCE vulnerability in Kali Forms plugin for WordPress and urges users to apply the available patch immediately.

    0001068
    604 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-3584 — CVSS 9.8/10 ██████████ The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/paYiMbE27a

    Post summary

    The post alerts that CVE‑2026‑3584 is a critical Remote Code Execution flaw in the Kali Forms WordPress plugin and that a patch is already available.

    1000044
    7 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Active Exploitation

    Hackers Actively Exploiting 9.8 Critical RCE Flaw in Kali Forms WordPress Plugin https://securityonline.info/kali-forms-vulnerability-wordpress-rce-cve-2026-3584/

    Post summary

    The post reports that hackers are actively exploiting a critical remote code execution flaw (CVE‑2026‑3584) in the Kali Forms WordPress plugin, highlighting the severity but providing no PoC or patch information.

    0000041
    243 followersView on X
  • N Shams@Nav_the_Sham
    Disclosure

    CVE-2026-3584 was published on March 20 with a CVSS 3.1 score of 9.8. This is a vulnerability in Kali Forms plugin, up to version 2.4.9, for WordPress that allows for RCE via the 'form_process' function. This vulnerability can be exploited by a user supplying a malicious 'key' which is mapped to internal placeholder values via the 'prepare_post_data' function. The plugin calls the 'call_user_func' function on those placeholder values/keys, which allows for unauthorized RCE on the exploited web server.

    Post summary

    The post discloses CVE-2026-3584, a high‑severity RCE flaw in Kali Forms plugin for WordPress, detailing how a malicious key invokes call_user_func to execute unauthorized code, but does not mention a PoC, active exploitation, or available patch.

    0000071
    339 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-3584 - Critical The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 via the 'form_process' function. This is due to the 'prepare_post_dat... https://www.thehackerwire.com/vulnerability/CVE-2026-3584/ https://t.co/LU4LxgZ16d

    Post summary

    CVE-2026-3584 enables remote code execution in Kali Forms WordPress plugin versions up to 2.4.9; no PoC, exploit, patch, or active exploitation is mentioned.

    0000046
    138 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-3584: Kali Forms <= 2.4.9 - Unauthentic... Unauthenticated RCE via `call_user_func` on user-controlled placeholders - classic PHP footgun that turns contact forms ... https://zerodaysignal.com/vulnerability/CVE-2026-3584 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑3584 affecting Kali Forms 2.4.9 or earlier, describing an unauthenticated remote code execution via PHP’s call_user_func. A link to a ZerodaySignal article is provided for further detail.

    0000060
    155 followersView on X

Explore more