Unauthenticated RCE in Hash Form Plugin for WordPress
An unauthenticated arbitrary file upload vulnerability (CVE-2026-81780) in the Hash Form WordPress plugin allows attackers to achieve remote code execution through the 'admin-ajax.php' endpoint.
CVE search metadata
CVE search record: CVE-2026-81780. Severity: critical. CVSS: 10.0. EPSS: 0.52%. KEV: no. Product: Hash Form (<= 1.4.2). Brief: Unauthenticated RCE in Hash Form Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hash-form-rce/
Hash Form, a WordPress plugin, contains a critical vulnerability (CVE-2026-81780) that allows unauthenticated attackers to upload arbitrary files to the server. The vulnerability resides in the hashform_file_upload_action action handled by the admin-ajax.php file. By manipulating the allowedExtensions[] parameter, an attacker can bypass file extension validation, enabling the upload of malicious PHP files into public-facing directories.
Publicly available exploits for this vulnerability are actively circulating as of October 2026. These exploits automate the scanning process, support multiple PHP-executable extensions (such as .php7, .pht, and .phar), and include advanced techniques to override server configurations via .htaccess if direct execution is blocked. Successful exploitation grants attackers remote code execution capabilities, allowing them to issue commands via the uploaded file. This vulnerability affects Hash Form versions 1.4.2 and earlier.
Attack Chain
- The attacker sends a GET request to
/wp-admin/admin-ajax.php?action=hashform_previewto extract the requiredajax_nounceparameter. - The attacker crafts a POST request to
/wp-admin/admin-ajax.php?action=hashform_file_upload_actioncontaining thefile_uploader_nonce. - The attacker sets the
allowedExtensions[]parameter to an arbitrary value to bypass the plugin's validation logic. - The attacker uploads a malicious PHP shell file using the
qqfileparameter within the POST body. - If the server prevents direct PHP execution, the attacker attempts to upload an .htaccess file to override server handlers.
- The attacker verifies the RCE by sending an HTTP GET request to the uploaded shell file with a command parameter (e.g.,
?c=id). - The attacker executes arbitrary system commands via the uploaded shell, leading to full server compromise.
Impact
Successful exploitation of CVE-2026-81780 leads to unauthenticated remote code execution on the WordPress server. This allows for complete data exfiltration, total site takeover, and potential lateral movement into the hosting infrastructure. Multiple public exploit scripts exist, significantly increasing the likelihood of widespread automated exploitation of vulnerable WordPress sites.
Recommendation
Prioritize patching all affected instances immediately.
- Update the Hash Form plugin to version 1.4.3 or later.
- If immediate patching is not possible, disable the Hash Form plugin entirely.
- Deploy a WAF rule to block requests to
admin-ajax.phpwhereaction=hashform_file_upload_actionif the request originates from untrusted sources. - Restrict execution permissions in the
wp-content/uploads/hashform/directory via server configuration (e.g.,.htaccessor Nginxlocationblocks). - Use the provided Sigma rule to detect attempts to invoke the vulnerable plugin action.
Immediate actions
Block access to /wp-admin/admin-ajax.php?action=hashform_file_upload_action at the WAF level.
Mitigations
Update Hash Form plugin to version 1.4.3 or higher.
CVE-2026-81780
Detection coverage 1
Detects CVE-2026-81780 Exploitation - Hash Form Arbitrary File Upload
criticalDetects exploitation attempts against the Hash Form plugin via the admin-ajax.php endpoint to upload arbitrary files.
Detection queries are available on the platform. Get full rules →