
Security researchers reported that the :
- March 2, 2026: Initial submission of the Remote Code Execution flaw via bug bounty reporting.
- March 5, 2026: Wordfence Premium, Care, and Response users received addressed the issue in version 2.4.10 of the WordPress plugin, while all versions up to and including 2.4.9 remained vulnerable.
Technical Root Cause Behind the Kali Forms Vulnerability
The core of this WordPress plugin flaw lies in how user-supplied form can inject arbitrary PHP function names. These are then executed directly, resulting in Remote Code Execution (RCE) attacks.
Researchers noted that the lack of input restrictions in prepare_post_data() enables overwriting internal placeholders. As a result, attacker-controlled values flow directly into call_user_func(), making exploitation trivial once the request is submitted.
One observed abuse pattern demonstrates authentication bypass attempts using built-in monitoring shows that exploitation began immediately after disclosure. Attackers have been systematically targeting the WordPress plugin using automated requests to admin-ajax.php.
A representative flaw is triggered through manipulated form submission data.
Security systems recorded significant attack volume:
- Over 312,200 exploit attempts were blocked targeting the Kali Forms vulnerability.
- Heavy targeting was observed immediately after March 20, 2026 disclosure.
- Increased spike in activity between April 4 and April 10, 2026.
Top Attacking IP Addresses Observed
Threat intelligence identified several IPs responsible for large-scale exploitation attempts:
- 209.146.60.26 – over 152,000 blocked requests
- 49.156.40.126 – over 50,000
- 124.248.183.139 – over 26,000
- 202.56.2.126 – over 14,000
- 130.12.182.154 – over 11,000
- 104.28.160.197 – over 9,000
- 1.53.114.181 – over 5,700
- 157.15.40.74 – over 3,000
- 114.10.99.126 – over 2,500
- 83.147.12.83 – over 1,300
These sources were repeatedly associated with exploitation attempts targeting the Kali Forms vulnerability in the affected WordPress plugin.↗ Original-Artikel auf thecyberexpress.com lesenVollständiger Original-BerichtAusführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf thecyberexpress.com.
SOCIAL SHARE CARD GENERATOR