CVE-2026-81780 is an unrestricted file-upload vulnerability affecting the Hash Form WordPress plugin through version 1.4.2. An unauthenticated remote attacker can upload arbitrary files through affected upload functionality. The issue is classified as CWE-434 and is rated CVSS v3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains one Python 3 exploit script, a README, and an MIT license. The script targets a claimed unauthenticated arbitrary-file-upload vulnerability in the Hash Form WordPress plugin (CVE-2026-81780, claimed affected through version 1.4.2). It fingerprints the plugin by requesting its readme.txt, parses its Stable tag, then requests Hash Form preview endpoints for form IDs 1-20 to recover an ajax_nounce token. It submits a raw PHP payload to the hashform_file_upload_action AJAX endpoint while naming the payload with alternate PHP-associated extensions (.phar, .phtml, .php5, and .php7). Successful uploads are expected under the predictable Hash Form temporary uploads path. The embedded PHP payload invokes system() on attacker-controlled c query input, resulting in remote command execution when the uploaded file is served as PHP. The script includes single-target, multithreaded list/batch processing, success logging to vuln.txt, TLS-verification disabling, and post-exploitation interactive-shell support. It is standalone rather than a known exploit-framework module, and uses a fixed, basic web-shell payload.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated arbitrary file-upload vulnerability affecting Hash Form versions 1.4.2 and earlier.
A critical unauthenticated arbitrary file-upload vulnerability affecting Hash Form versions 1.4.2 and earlier. Its network-accessible, no-authentication, no-user-interaction attack path and complete confidentiality, integrity, and availability impact could enable remote code execution depending on server configuration and uploaded file handling.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.