Skip to content
Threat Feed
critical advisory

Unauthenticated RCE in Hash Form Plugin for WordPress

An unauthenticated arbitrary file upload vulnerability (CVE-2026-81780) in the Hash Form WordPress plugin allows attackers to achieve remote code execution through the 'admin-ajax.php' endpoint.

CVE search metadata

CVE search record: CVE-2026-81780. Severity: critical. CVSS: 10.0. EPSS: 0.52%. KEV: no. Product: Hash Form (<= 1.4.2). Brief: Unauthenticated RCE in Hash Form Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hash-form-rce/

Hash Form, a WordPress plugin, contains a critical vulnerability (CVE-2026-81780) that allows unauthenticated attackers to upload arbitrary files to the server. The vulnerability resides in the hashform_file_upload_action action handled by the admin-ajax.php file. By manipulating the allowedExtensions[] parameter, an attacker can bypass file extension validation, enabling the upload of malicious PHP files into public-facing directories.

Publicly available exploits for this vulnerability are actively circulating as of October 2026. These exploits automate the scanning process, support multiple PHP-executable extensions (such as .php7, .pht, and .phar), and include advanced techniques to override server configurations via .htaccess if direct execution is blocked. Successful exploitation grants attackers remote code execution capabilities, allowing them to issue commands via the uploaded file. This vulnerability affects Hash Form versions 1.4.2 and earlier.

Attack Chain

  1. The attacker sends a GET request to /wp-admin/admin-ajax.php?action=hashform_preview to extract the required ajax_nounce parameter.
  2. The attacker crafts a POST request to /wp-admin/admin-ajax.php?action=hashform_file_upload_action containing the file_uploader_nonce.
  3. The attacker sets the allowedExtensions[] parameter to an arbitrary value to bypass the plugin's validation logic.
  4. The attacker uploads a malicious PHP shell file using the qqfile parameter within the POST body.
  5. If the server prevents direct PHP execution, the attacker attempts to upload an .htaccess file to override server handlers.
  6. The attacker verifies the RCE by sending an HTTP GET request to the uploaded shell file with a command parameter (e.g., ?c=id).
  7. The attacker executes arbitrary system commands via the uploaded shell, leading to full server compromise.

Impact

Successful exploitation of CVE-2026-81780 leads to unauthenticated remote code execution on the WordPress server. This allows for complete data exfiltration, total site takeover, and potential lateral movement into the hosting infrastructure. Multiple public exploit scripts exist, significantly increasing the likelihood of widespread automated exploitation of vulnerable WordPress sites.

Recommendation

Prioritize patching all affected instances immediately.

  • Update the Hash Form plugin to version 1.4.3 or later.
  • If immediate patching is not possible, disable the Hash Form plugin entirely.
  • Deploy a WAF rule to block requests to admin-ajax.php where action=hashform_file_upload_action if the request originates from untrusted sources.
  • Restrict execution permissions in the wp-content/uploads/hashform/ directory via server configuration (e.g., .htaccess or Nginx location blocks).
  • Use the provided Sigma rule to detect attempts to invoke the vulnerable plugin action.

Immediate actions

Block access to /wp-admin/admin-ajax.php?action=hashform_file_upload_action at the WAF level.

SOC 2h

Mitigations

Update Hash Form plugin to version 1.4.3 or higher.

immediate IT Operations

CVE-2026-81780

Detection coverage 1

Detects CVE-2026-81780 Exploitation - Hash Form Arbitrary File Upload

critical

Detects exploitation attempts against the Hash Form plugin via the admin-ajax.php endpoint to upload arbitrary files.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →