CRITICAL 10 CVE-2026-81780 Published 31 Aug 2026

Hash Form Plugin File Upload Vulnerability

Worried this affects one of your servers?

Hash Form, a WordPress plugin, is affected by an unauthenticated arbitrary file upload vulnerability in versions up to 1.4.2.

This flaw allows attackers to upload malicious files without any authentication, potentially leading to remote code execution.

  • Affected versions: <= 1.4.2
  • Impact: Unauthenticated file upload, potential remote code execution

Reference: CVE-2026-81780 on NVD

← Back to Security News