{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hash-form--1.4.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hash_form:hash_form:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-81780"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hash Form (\u003c= 1.4.2)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","arbitrary-file-upload","rce","webserver"],"_cs_type":"advisory","_cs_vendors":["Hash Form"],"content_html":"\u003cp\u003eHash Form, a WordPress plugin, contains a critical vulnerability (CVE-2026-81780) that allows unauthenticated attackers to upload arbitrary files to the server. The vulnerability resides in the \u003ccode\u003ehashform_file_upload_action\u003c/code\u003e action handled by the \u003ccode\u003eadmin-ajax.php\u003c/code\u003e file. By manipulating the \u003ccode\u003eallowedExtensions[]\u003c/code\u003e parameter, an attacker can bypass file extension validation, enabling the upload of malicious PHP files into public-facing directories.\u003c/p\u003e\n\u003cp\u003ePublicly available exploits for this vulnerability are actively circulating as of October 2026. These exploits automate the scanning process, support multiple PHP-executable extensions (such as .php7, .pht, and .phar), and include advanced techniques to override server configurations via .htaccess if direct execution is blocked. Successful exploitation grants attackers remote code execution capabilities, allowing them to issue commands via the uploaded file. This vulnerability affects Hash Form versions 1.4.2 and earlier.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker sends a GET request to \u003ccode\u003e/wp-admin/admin-ajax.php?action=hashform_preview\u003c/code\u003e to extract the required \u003ccode\u003eajax_nounce\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a POST request to \u003ccode\u003e/wp-admin/admin-ajax.php?action=hashform_file_upload_action\u003c/code\u003e containing the \u003ccode\u003efile_uploader_nonce\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker sets the \u003ccode\u003eallowedExtensions[]\u003c/code\u003e parameter to an arbitrary value to bypass the plugin's validation logic.\u003c/li\u003e\n\u003cli\u003eThe attacker uploads a malicious PHP shell file using the \u003ccode\u003eqqfile\u003c/code\u003e parameter within the POST body.\u003c/li\u003e\n\u003cli\u003eIf the server prevents direct PHP execution, the attacker attempts to upload an .htaccess file to override server handlers.\u003c/li\u003e\n\u003cli\u003eThe attacker verifies the RCE by sending an HTTP GET request to the uploaded shell file with a command parameter (e.g., \u003ccode\u003e?c=id\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe attacker executes arbitrary system commands via the uploaded shell, leading to full server compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-81780 leads to unauthenticated remote code execution on the WordPress server. This allows for complete data exfiltration, total site takeover, and potential lateral movement into the hosting infrastructure. Multiple public exploit scripts exist, significantly increasing the likelihood of widespread automated exploitation of vulnerable WordPress sites.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all affected instances immediately.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Hash Form plugin to version 1.4.3 or later.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable the Hash Form plugin entirely.\u003c/li\u003e\n\u003cli\u003eDeploy a WAF rule to block requests to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e where \u003ccode\u003eaction=hashform_file_upload_action\u003c/code\u003e if the request originates from untrusted sources.\u003c/li\u003e\n\u003cli\u003eRestrict execution permissions in the \u003ccode\u003ewp-content/uploads/hashform/\u003c/code\u003e directory via server configuration (e.g., \u003ccode\u003e.htaccess\u003c/code\u003e or Nginx \u003ccode\u003elocation\u003c/code\u003e blocks).\u003c/li\u003e\n\u003cli\u003eUse the provided Sigma rule to detect attempts to invoke the vulnerable plugin action.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T13:41:30Z","date_published":"2026-10-07T13:41:30Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hash-form-rce/","summary":"An unauthenticated arbitrary file upload vulnerability (CVE-2026-81780) in the Hash Form WordPress plugin allows attackers to achieve remote code execution through the 'admin-ajax.php' endpoint.","title":"Unauthenticated RCE in Hash Form Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-hash-form-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Hash Form (\u003c= 1.4.2)","version":"https://jsonfeed.org/version/1.1"}