Unauthenticated Arbitrary File Upload in Hash Form Plugin by WordPress
CVE-2026-81780
10CRITICAL
What is CVE-2026-81780?
The Hash Form Plugin for WordPress, specifically versions up to 1.4.2, is vulnerable to an unauthenticated arbitrary file upload. This vulnerability allows attackers to upload malicious files without authentication, potentially compromising the security of the web application and leading to unauthorized access or data breaches.
Affected Version(s)
Hash Form <= 1.4.2