Medium 4.3
2025-05-07< 1.2.9
CVE-2025-47468
Minimum safe version
1.2.9
Update to 1.2.9 or later to address 5 fixable vulnerabilities
CVE-2025-47468
CVE-2024-12201
WordPress Hash Form Plugin <= 1.1.9 is vulnerable to Arbitrary File Upload
WordPress Hash Form – Drag & Drop Form Builder Plugin <= 1.1.0 is vulnerable to PHP Object Injection
WordPress Hash Form – Drag & Drop Form Builder Plugin <= 1.1.0 is vulnerable to Remote Code Execution (RCE)