S4E just found a medium snmp system information scanner
critical·Product Based Web Vulnerabilities·Updated Jul 15, 2024

CVE-2024-5084 Scanner

CVE-2024-5084 scanner - Arbitrary File Upload vulnerability in Hash Form Drag & Drop Form Builder plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-5084
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Hash Form – Drag & Drop Form Builderby hashthemes
0
drag_and_drop_form_builderby hashthemes
0
Updated Aug 22, 2026View on NVD →
Detail

Hash Form Drag & Drop Form Builder plugin for WordPress is a widely used tool for creating customizable forms on WordPress websites. It is utilized by website administrators and developers to enable drag-and-drop form creation without needing extensive coding knowledge. This plugin is popular due to its ease of use and flexibility. However, it is critical that users keep it updated to avoid potential vulnerabilities. The plugin is used across various industries for managing form submissions and user interactions on WordPress sites.

The Hash Form Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This allows unauthenticated attackers to upload arbitrary files to the server. Exploiting this vulnerability could lead to remote code execution. The issue is critical and needs immediate attention to mitigate risks.

The vulnerability lies in the 'file_upload_action' function of the Hash Form Drag & Drop Form Builder plugin, where there is a lack of proper file type validation. Attackers can exploit this by sending a specially crafted request to the server, allowing them to upload arbitrary files. This includes malicious scripts that could be executed on the server, potentially leading to full control over the affected website. The vulnerable endpoint is 'admin-ajax.php?action=hashform_file_upload_action' and the 'qqfile' parameter is the one being exploited.

If exploited, this vulnerability could allow attackers to upload and execute malicious files on the server, potentially leading to remote code execution. This could result in complete control over the affected WordPress site, data theft, defacement, and the use of the server for malicious activities such as distributing malware. The integrity, confidentiality, and availability of the website and its data could be severely compromised.

By using the S4E platform, you can proactively manage and mitigate cybersecurity threats to your digital assets. Our platform offers comprehensive vulnerability scanning, detailed reporting, and actionable remediation steps to ensure your systems are secure. Join us to benefit from our user-friendly interface, continuous monitoring, and expert support, helping you stay ahead of potential threats and protect your digital presence effectively.

References:

Solution Advice
  • Update the Hash Form Drag & Drop Form Builder plugin to version 1.1.1 or higher.
  • Implement strict file type validation on all file upload functionalities.
  • Regularly monitor and audit your website for unusual file uploads and activities.
  • Employ a Web Application Firewall (WAF) to block malicious file upload attempts.
  • Ensure proper permissions are set on upload directories to restrict executable files.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.