Hash Form – Drag & Drop Form Builder <= 1.4.0 - Cross-Site Request Forgery
medium
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged r...
- CVSS:
- 4.3
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.1
- Disclosed:
- Aug 24, 2026
CVE-2026-78280 on NVD →
Hash Form <= 1.2.8 - Cross-Site Request Forgery
medium
The Hash Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.8. This is due to missing or incorrect nonce validation on the add_more_condition_block() function. This makes it possible for unauthenticated attackers to update block conditions via a forged request gr...
- CVSS:
- 4.3
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.9
- Disclosed:
- May 7, 2025
CVE-2025-47468 on NVD →
Hash Form – Drag & Drop Form Builder [hash-form] < 1.2.9
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in hashthemes Hash Form allows Cross Site Request Forgery. This issue affects Hash Form: from n/a through 1.2.8.
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9
- Disclosed:
- May 7, 2025
CVE-2025-47468 on NVD →
Hash Form – Drag & Drop Form Builder [hash-form] < 1.2.2
unknown
[en] The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check when creating form styles in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create new form...
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Dec 12, 2024
CVE-2024-12201 on NVD →
Hash Form <= 1.2.1 - Missing Authorization to Authenticated (Contributor+) Form Style Creation
medium
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check when creating form styles in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to create new form styl...
- CVSS:
- 4.3
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Dec 11, 2024
CVE-2024-12201 on NVD →
Hash Form – Drag & Drop Form Builder [hash-form] < 1.2.0
unknown
[en] The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to upload files that are excluded from bot...
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Oct 5, 2024
CVE-2024-9417 on NVD →
Hash Form - Drag & Drop Form Builder <= 1.1.9 - Unauthenticated Limited File Upload
medium
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to upload files that are excluded from both the...
- CVSS:
- 6.1
- Affected:
- up to 1.1.9
- Fixed in:
- 1.2.0
- Disclosed:
- Oct 4, 2024
CVE-2024-9417 on NVD →
Hash Form – Drag & Drop Form Builder [hash-form] < 1.1.1
unknown
[en] The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected...
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- May 23, 2024
CVE-2024-5084 on NVD →
Hash Form – Drag & Drop Form Builder [hash-form] < 1.1.1
unknown
[en] The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is...
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- May 23, 2024
CVE-2024-5085 on NVD →
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
critical
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site'...
- CVSS:
- 9.8
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- May 22, 2024
CVE-2024-5084 on NVD →
Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object Injection
high
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is prese...
- CVSS:
- 8.1
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- May 22, 2024
CVE-2024-5085 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database