Cross Site Request Forgery Vulnerability in Hash Form Plugin by WordPress
CVE-2026-78280
4.3MEDIUM
What is CVE-2026-78280?
An unauthenticated Cross Site Request Forgery (CSRF) vulnerability was discovered in the Hash Form plugin for WordPress, affecting all versions up to 1.4.0. This vulnerability allows attackers to exploit the plugin without authentication, potentially leading to unauthorized actions being performed on behalf of legitimate users. Site administrators should take immediate action to update the plugin to protect against possible exploitation and ensure the security of their web applications.
Affected Version(s)
Hash Form <= 1.4.0