Executive brief
Hash Form is a WordPress plugin used to create customizable forms on websites. The plugin contains an unauthenticated file upload vulnerability that allows attackers to upload malicious files to the server without logging in, potentially leading to complete server compromise and website takeover. This is a critical risk affecting any WordPress site using vulnerable versions of the plugin.
Technical details
The vulnerability is an unauthenticated arbitrary file upload flaw in the Hash Form WordPress plugin versions 1.4.2 and earlier. The vulnerability allows attackers to upload malicious files to the server without authentication, due to missing or inadequate file upload validation. An attacker can exploit this over the network by submitting a file upload request to the vulnerable endpoint. Once a malicious file is uploaded, the attacker can execute arbitrary code on the server, leading to full server compromise. The vulnerability has been patched in version 1.4.3 and later.
Affected products
- HashThemes Hash Form <=1.4.2
Timeline
- 2026-08-28: disclosed: Vulnerability reported to Patchstack
- 2026-08-31: advisory: CVE-2026-81780 published
- 2026-08-28: patched: Patched in version 1.4.3