CVE-2026-78292: WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability
Published Aug 27, 2026
·Updated
Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.
Affected Software
1 affected component
WordPress Hash Form plugin<=1.4.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Hash Form Pluginto a version that resolves this vulnerability.Fixed in 1.4.2
Event History
Aug 27, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation.
2
Are installations running version 1.4.1 affected?
Yes. The affected range includes Hash Form plugin version 1.4.1 and earlier.
3
What is the potential impact of successful exploitation?
The supplied severity vector indicates remote exploitation with low attack complexity and no user interaction, with high potential impact to confidentiality, integrity, and availability.