Junglewise Threat Intelligence

CVE-2026-78280: HashThemes Hash Form cross-site request forgery

CVE-2026-78280 · Severity: medium · CVSS 4.3 · Published 2026-08-24

Executive brief

Hash Form is a WordPress form-building plugin used by site administrators to create and manage web forms. An unauthenticated attacker can trick a logged-in admin into performing unintended actions—such as modifying form settings or configurations—by crafting a malicious webpage, without the user's knowledge or consent. This could lead to unauthorized changes to critical site functionality.

Technical details

The vulnerability is a Cross-Site Request Forgery (CSRF) flaw in Hash Form plugin versions 1.4.0 and earlier. The plugin fails to properly validate or protect against cross-site requests, allowing an attacker to forge requests that execute actions on behalf of authenticated administrators. Attack requires user interaction: a logged-in admin must be tricked into visiting an attacker-controlled page. An attacker can modify form configurations, settings, or other admin-level functionality without the user's consent. The vulnerability is patched in version 1.4.1 and later.

Affected products

  • HashThemes Hash Form <= 1.4.0

Timeline

  • 2026-08-24: disclosed: Published by Patchstack
  • 2026-08-24: patched: Fixed in version 1.4.1

References

Related threats