Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hashthemes

First CVE: Nov 1, 2021Active for: 5 yearsTotal CVEs: 13
32.4
VTI Score
Medium

Hashthemes develops WordPress plugins and themes for website building and form management, a modestly represented vendor within a niche but more prominent segment of the plugin ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability; the exposure recurs across products such as Hash Elements and Hash Form through web-layer weakness classes including cross-site scripting, missing authorization checks, unrestricted file uploads, and unsafe deserialization that are characteristic of plugin-based content management. Defenders should treat WordPress installations running these plugins as requiring timely security patching; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hashthemes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 1, 2021
4 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-5084CRITICAL
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in al
May 23, 20249.876NOYES
CVE-2024-5085CRITICAL
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted inp
May 23, 20249.829NONO
CVE-2026-65483MEDIUM
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions.
Jul 23, 20265.926NONO
CVE-2021-39333HIGH
The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, all
Nov 1, 20218.126NONO
CVE-2026-24618MEDIUM
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Ha
Jun 12, 20264.322NONO
CVE-2025-22296MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Hash Elements hash-elements.This issue affects Hash Elements: from
Jan 7, 20256.519NONO
CVE-2024-10802MEDIUM
The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_title_by_id() function in all v
Nov 13, 20245.318NONO
CVE-2024-9417MEDIUM
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in al
Oct 5, 20246.118NONO
CVE-2024-5177MEDIUM
The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter within multiple widgets in all versions up to, and including, 1.3.8 due
May 23, 20245.416NONO
CVE-2024-30426MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Hash Elements allows Stored XSS.This issue affects Hash Elements: f
Mar 29, 20245.416NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
77%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (53.8%)
Unknown0 (0.0%)
Required6 (46.2%)
Privileges Required
Low7 (53.8%)
High1 (7.7%)
None5 (38.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
7.7% of CVEs· 98th percentile
Nuclei
1 CVE
7.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hashthemes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hashthemes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hashthemes's Products

View all 2 CNAs →

Top CWEs