CVE-2025-47468: WordPress Hash Form plugin <= 1.2.8 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in hashthemes Hash Form allows Cross Site Request Forgery. This issue affects Hash Form: from n/a through 1.2.8.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in hashthemes Hash Form hash-form allows Cross Site Request Forgery.This issue affects Hash Form: from n/a through <= 1.2.8.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47468?
CVE-2025-47468 is classified as a medium severity Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-47468?
To mitigate CVE-2025-47468, update the Hashthemes Hash Form plugin to version 1.2.9 or later.
What versions are affected by CVE-2025-47468?
CVE-2025-47468 affects all versions of Hashthemes Hash Form up to and including 1.2.8.
What type of vulnerability is CVE-2025-47468?
CVE-2025-47468 is a Cross-Site Request Forgery (CSRF) vulnerability that allows unauthorized actions to be performed.
Who is affected by CVE-2025-47468?
Users of the Hashthemes Hash Form plugin on WordPress sites using version 1.2.8 or earlier are affected by CVE-2025-47468.