CVE-2026-81780: WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Hash Form pluginto a version that resolves this vulnerability.Fixed in 1.4.3 - Compensating control
Consider uninstalling or disabling the WordPress Hash Form plugin until it is updated, because versions <= 1.4.2 are vulnerable to unauthenticated arbitrary file upload.
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
Which installations are affected?
WordPress sites using the Hash Form plugin at version 1.4.2 or earlier are affected according to the provided information.
What is the likely impact of a successful exploit?
A successful attacker can upload arbitrary files. The listed CVSS vector rates confidentiality, integrity, and availability impact as high, with scope changed.