CVE-2026-81780
published 2026-08-31CVE-2026-81780: Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
PriorityP270critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.29%
21.8th percentile
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hashthemes | hash_form | n/a – 1.4.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
ghsa_unreviewed·2026-08-31
CVE-2026-81780 [CRITICAL] CWE-434 Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
VulDB
Hashmes Hash Form Plugin up to 1.4.2 on WordPress unrestricted upload
vuldb·2026-08-31·CVSS 10.0
CVE-2026-81780 [CRITICAL] Hashmes Hash Form Plugin up to 1.4.2 on WordPress unrestricted upload
A vulnerability identified as critical has been detected in Hashmes Hash Form Plugin up to 1.4.2 on WordPress. The affected element is an unknown function. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2026-81780. It is possible to initiate the attack remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-31
Published