CVE-2026-78280: WordPress Hash Form plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.
Affected Software
1 affected component
WordPress Hash Form plugin<=1.4.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Hash Form Pluginto a version that resolves this vulnerability.Fixed in 1.4.1
Event History
Aug 24, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What user interaction is required for exploitation?
An attacker must persuade a user to interact with a crafted request. The vulnerability is remotely reachable and does not require the attacker to be authenticated.
2
What security impact is identified?
The listed impact is limited to integrity, meaning an attacker may cause unauthorized changes through a victim's session. No confidentiality or availability impact is identified.