Impact
WordPress Hash Form plugin versions 1.4.1 and earlier contain an unauthenticated PHP Object Injection flaw that allows an attacker to craft a malicious serialized object and submit it through the plugin’s public endpoints. Because the plugin does not perform proper input validation, the deserialized object can instantiate arbitrary PHP objects, which in turn can trigger execution of code on the server. This vulnerability can lead to a full compromise of the affected WordPress installation, allowing the attacker to read or modify sensitive data, install malware, or pivot to other systems on the network.
Affected Systems
Vendors: Hash Themes, Product: Hash Form. All installations of Hash Form plugin 1.4.1 or earlier are affected. Any WordPress site that has this plugin enabled is at risk.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the vulnerability is unauthenticated, meaning an attacker does not need any credentials to exploit it. While no EPSS score is reported, the lack of a KEV listing does not reduce the risk; the flaw remains highly attractive for automated exploitation. Attackers can trigger it by sending a crafted payload to the Hash Form plugin’s public interface, often from any user via a standard HTTP request.
OpenCVE Enrichment