Vulnerability record · CVE-2024-5084 · published 23 May 2024
CVE-2024-5084: Hash Form WordPress plugin unauthenticated arbitrary file upload
Hashthemes · Hash Form
The Hash Form drag-and-drop form builder plugin for WordPress fails to validate file types in its 'file_upload_action' function in all versions up to and including 1.1.0. This lets unauthenticated attackers upload arbitrary files to the site's server, which can lead to remote code execution.
Description
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, and high EPSS probability, make this an urgent risk for any site running the vulnerable plugin.
What it is
The Hash Form drag-and-drop form builder plugin for WordPress fails to validate file types in its 'file_upload_action' function in all versions up to and including 1.1.0. This lets unauthenticated attackers upload arbitrary files to the site's server, which can lead to remote code execution.
Impact
An attacker can place executable files on the server and potentially run code, taking full control of the WordPress site. This can lead to data theft, defacement, or use of the site as a foothold for further attacks.
Attack surface
The flaw is reachable over the network through the plugin's file upload action, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Any site running the vulnerable plugin version exposes this endpoint.
Exploitation
The CVE is not listed in CISA KEV, but EPSS is high at 0.50653 (98.9th percentile), indicating a strong likelihood of exploitation. No public exploit or ransomware usage is documented in the record.
What to do
- Update the Hash Form plugin to a version newer than 1.1.0 as soon as possible.
- If an update is not immediately possible, disable or remove the plugin.
- Restrict file uploads at the web server or WAF level to block executable file types.
- Audit the uploads directory for unexpected or executable files and remove any found.
- Monitor WordPress plugin advisories for further updates.
Detection
- Monitor the WordPress uploads directory for newly created files with executable extensions (e.g., .php, .phtml).
- Review web server logs for POST requests to the plugin's file upload endpoint, especially from unauthenticated sources.
- Use file integrity monitoring to alert on unexpected file changes in web-accessible directories.
- Check for outbound connections or processes spawned by the web server that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-5084 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-5084), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.