← Back to overview

A critical unauthenticated PHP Object Injection vulnerability has been identified in the Hash Form WordPress plugin affecting versions 1.4.1 and below. The vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to remote code execution or other serious impacts depending on available POP chains. The flaw is tracked as CVE-2026-78292 and has been documented by both NVD and Patchstack. No authentication is required to exploit this vulnerability, significantly increasing its risk profile. WordPress site administrators using Hash Form versions up to and including 1.4.1 are advised to update immediately. The vulnerability has been assigned a high criticality rating.

Affected products

  • Hash Form WordPress Plugin <= 1.4.1

Related CVE's

  • CVE-2026-78292

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities