← Terug naar overzicht

CVE-2026-81780 describes an unauthenticated arbitrary file upload vulnerability affecting the Hash Form WordPress plugin in versions 1.4.2 and below. This vulnerability allows unauthenticated attackers to upload arbitrary files to the affected WordPress site, which could lead to remote code execution. The flaw is particularly critical because no authentication is required to exploit it, greatly expanding the potential attack surface. The vulnerability was documented by both the NVD (National Vulnerability Database) and Patchstack. Users of the Hash Form plugin are advised to update to a patched version immediately. Arbitrary file upload vulnerabilities are commonly leveraged by attackers to plant web shells or malicious scripts on compromised servers. The severity is rated High due to the unauthenticated nature and potential for full site compromise.

Affected products

  • Hash Form WordPress Plugin <= 1.4.2

Related CVE's

  • CVE-2026-81780

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities