Junglewise Threat Intelligence

CVE-2026-81780: Hash Form arbitrary file upload

CVE-2026-81780 · Severity: critical · CVSS 10 · Published 2026-08-31

Executive brief

Hash Form is a WordPress plugin used to create customizable forms on websites. The plugin contains an unauthenticated file upload vulnerability that allows attackers to upload malicious files to the server without logging in, potentially leading to complete server compromise and website takeover. This is a critical risk affecting any WordPress site using vulnerable versions of the plugin.

Technical details

The vulnerability is an unauthenticated arbitrary file upload flaw in the Hash Form WordPress plugin versions 1.4.2 and earlier. The vulnerability allows attackers to upload malicious files to the server without authentication, due to missing or inadequate file upload validation. An attacker can exploit this over the network by submitting a file upload request to the vulnerable endpoint. Once a malicious file is uploaded, the attacker can execute arbitrary code on the server, leading to full server compromise. The vulnerability has been patched in version 1.4.3 and later.

Affected products

  • HashThemes Hash Form <=1.4.2

Timeline

  • 2026-08-28: disclosed: Vulnerability reported to Patchstack
  • 2026-08-31: advisory: CVE-2026-81780 published
  • 2026-08-28: patched: Patched in version 1.4.3

References

Related threats