Hashthemes develops WordPress plugins and themes for website building and form management, a modestly represented vendor within a niche but more prominent segment of the plugin ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability; the exposure recurs across products such as Hash Elements and Hash Form through web-layer weakness classes including cross-site scripting, missing authorization checks, unrestricted file uploads, and unsafe deserialization that are characteristic of plugin-based content management. Defenders should treat WordPress installations running these plugins as requiring timely security patching; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hashthemes over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5084CRITICAL The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in al | May 23, 2024 | 9.8 | 76 | NO | YES |
CVE-2024-5085CRITICAL The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted inp | May 23, 2024 | 9.8 | 29 | NO | NO |
CVE-2026-65483MEDIUM Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. | Jul 23, 2026 | 5.9 | 26 | NO | NO |
CVE-2021-39333HIGH The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, all | Nov 1, 2021 | 8.1 | 26 | NO | NO |
CVE-2026-24618MEDIUM Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data.
This issue affects Ha | Jun 12, 2026 | 4.3 | 22 | NO | NO |
CVE-2025-22296MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Hash Elements hash-elements.This issue affects Hash Elements: from | Jan 7, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-10802MEDIUM The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_title_by_id() function in all v | Nov 13, 2024 | 5.3 | 18 | NO | NO |
CVE-2024-9417MEDIUM The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in al | Oct 5, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-5177MEDIUM The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter within multiple widgets in all versions up to, and including, 1.3.8 due | May 23, 2024 | 5.4 | 16 | NO | NO |
CVE-2024-30426MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements allows Stored XSS.This issue affects Hash Elements: f | Mar 29, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hashthemes.
Media articles that mention a CVE ID that affects a product developed by Hashthemes — matched by CVE ID, not by vendor name.