CVE-2026-78292CRITICAL NVDCVSS Score 9.8Severity CRITICALPublished Aug 27, 2026Vendor unknownDescriptionUnauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.Referenceshttps://patchstack.com/database/wordpress/plugin/hash-form/vulnerability/wordpress-hash-form-plugin-1-4-1-php-object-injection-vulnerability?_s_id=cve