Executive brief
Hash Form is a WordPress form-building plugin used by site administrators to create and manage web forms. An unauthenticated attacker can trick a logged-in admin into performing unintended actions—such as modifying form settings or configurations—by crafting a malicious webpage, without the user's knowledge or consent. This could lead to unauthorized changes to critical site functionality.
Technical details
The vulnerability is a Cross-Site Request Forgery (CSRF) flaw in Hash Form plugin versions 1.4.0 and earlier. The plugin fails to properly validate or protect against cross-site requests, allowing an attacker to forge requests that execute actions on behalf of authenticated administrators. Attack requires user interaction: a logged-in admin must be tricked into visiting an attacker-controlled page. An attacker can modify form configurations, settings, or other admin-level functionality without the user's consent. The vulnerability is patched in version 1.4.1 and later.
Affected products
- HashThemes Hash Form <= 1.4.0
Timeline
- 2026-08-24: disclosed: Published by Patchstack
- 2026-08-24: patched: Fixed in version 1.4.1