This week in Wordfence Security News (Week of Mar 30, 2026):
- Over 200,000 WordPress sites at risk from an unauthenticated arbitrary file move vulnerability in the MW WP Form plugin, allowing full site takeover
- Massive spike in exploitation attempts targeting the Kali Forms RCE vulnerability, with activity increasing over 60x week-over-week
- A major supply chain attack compromises the widely used Axios JavaScript library, distributing backdoored versions to developers worldwide Active exploitation of a critical Citrix NetScaler vulnerability enabling session hijacking and potential full appliance compromise
- European Commission confirms a cloud breach with data theft claims by ShinyHunters
- Cisco internal development environment breached via poisoned Trivy supply chain attack, exposing source code and credentials
Timestamps:
0:00 Introduction
0:30 MW WP Form Vulnerability
1:15 Kali Forms Exploitation Surge
1:55 Axios Supply Chain Attack
3:20 Citrix NetScaler Active Exploitation
4:57 European Commission Breach
5:50 Cisco Dev Environment Breach
6:47 Wrap up discussion
Story Links:
- MW WP Form Vulnerability
- Kali Forms Exploitation Update
- Axios Supply Chain Attack (Wiz)
- Citrix NetScaler Advisory
- European Commission Breach (Bloomberg)
- Cisco / Trivy Supply Chain Attack
Stay informed and secure: get the latest WordPress security news on the Wordfence blog or subscribe to the WordPress Security Newsletter.