Extension WordPress
Vulnérabilités Hash Form – Drag & Drop Form Builder
Cette page rassemble les failles publiées pour Hash Form – Drag & Drop Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Hash Form – Drag & Drop Form Builder
5 fiches
Hash Form <= 1.2.8 – Cross-Site Request Forgery
The Hash Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.8. This is due to missing or incorrect nonce validation on the add_more_condition_block() function. This makes it possible for unauthenticated…
*-1.2.8
1.2.9
07/05/2025
Hash Form <= 1.2.1 – Missing Authorization to Authenticated (Contributor+) Form Style Creation
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check when creating form styles in all versions up to, and including, 1.2.1. This makes it…
*-1.2.1
1.2.2
11/12/2024
Hash Form – Drag & Drop Form Builder <= 1.1.9 – Unauthenticated Limited File Upload
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9. This…
*-1.1.9
1.2.0
04/10/2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 – Unauthenticated Arbitrary File Upload to Remote Code Execution
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes…
*-1.1.0
1.1.1
22/05/2024
Hash Form – Drag & Drop Form Builder <= 1.1.0 – Unauthenticated PHP Object Injection
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function. This makes it…
*-1.1.0
1.1.1
22/05/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.