Vendor
An unauthenticated arbitrary file upload vulnerability (CVE-2026-81780) in the Hash Form WordPress plugin allows attackers to achieve remote code execution through the 'admin-ajax.php' endpoint.