CVE-2026-81780CRITICAL NVDCVSS Score 10Severity CRITICALPublished Aug 31, 2026Vendor unknownDescriptionUnauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.Referenceshttps://patchstack.com/database/wordpress/plugin/hash-form/vulnerability/wordpress-hash-form-plugin-1-4-2-arbitrary-file-upload-vulnerability?_s_id=cve