<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:hash_form:hash_form:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ahash_formhash_form/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 13:41:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ahash_formhash_form/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated RCE in Hash Form Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-hash-form-rce/</link><pubDate>Wed, 07 Oct 2026 13:41:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-hash-form-rce/</guid><description>An unauthenticated arbitrary file upload vulnerability (CVE-2026-81780) in the Hash Form WordPress plugin allows attackers to achieve remote code execution through the 'admin-ajax.php' endpoint.</description><content:encoded><![CDATA[<p>Hash Form, a WordPress plugin, contains a critical vulnerability (CVE-2026-81780) that allows unauthenticated attackers to upload arbitrary files to the server. The vulnerability resides in the <code>hashform_file_upload_action</code> action handled by the <code>admin-ajax.php</code> file. By manipulating the <code>allowedExtensions[]</code> parameter, an attacker can bypass file extension validation, enabling the upload of malicious PHP files into public-facing directories.</p>
<p>Publicly available exploits for this vulnerability are actively circulating as of October 2026. These exploits automate the scanning process, support multiple PHP-executable extensions (such as .php7, .pht, and .phar), and include advanced techniques to override server configurations via .htaccess if direct execution is blocked. Successful exploitation grants attackers remote code execution capabilities, allowing them to issue commands via the uploaded file. This vulnerability affects Hash Form versions 1.4.2 and earlier.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker sends a GET request to <code>/wp-admin/admin-ajax.php?action=hashform_preview</code> to extract the required <code>ajax_nounce</code> parameter.</li>
<li>The attacker crafts a POST request to <code>/wp-admin/admin-ajax.php?action=hashform_file_upload_action</code> containing the <code>file_uploader_nonce</code>.</li>
<li>The attacker sets the <code>allowedExtensions[]</code> parameter to an arbitrary value to bypass the plugin's validation logic.</li>
<li>The attacker uploads a malicious PHP shell file using the <code>qqfile</code> parameter within the POST body.</li>
<li>If the server prevents direct PHP execution, the attacker attempts to upload an .htaccess file to override server handlers.</li>
<li>The attacker verifies the RCE by sending an HTTP GET request to the uploaded shell file with a command parameter (e.g., <code>?c=id</code>).</li>
<li>The attacker executes arbitrary system commands via the uploaded shell, leading to full server compromise.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-81780 leads to unauthenticated remote code execution on the WordPress server. This allows for complete data exfiltration, total site takeover, and potential lateral movement into the hosting infrastructure. Multiple public exploit scripts exist, significantly increasing the likelihood of widespread automated exploitation of vulnerable WordPress sites.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching all affected instances immediately.</p>
<ul>
<li>Update the Hash Form plugin to version 1.4.3 or later.</li>
<li>If immediate patching is not possible, disable the Hash Form plugin entirely.</li>
<li>Deploy a WAF rule to block requests to <code>admin-ajax.php</code> where <code>action=hashform_file_upload_action</code> if the request originates from untrusted sources.</li>
<li>Restrict execution permissions in the <code>wp-content/uploads/hashform/</code> directory via server configuration (e.g., <code>.htaccess</code> or Nginx <code>location</code> blocks).</li>
<li>Use the provided Sigma rule to detect attempts to invoke the vulnerable plugin action.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>arbitrary-file-upload</category><category>rce</category><category>webserver</category></item></channel></rss>