PatchSiren

HashThemes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL HashThemes CVE published 2026-08-20

CVE-2026-28164

A Cross-Site Request Forgery (CSRF) vulnerability exists in Easy Elementor Addons, affecting versions from n/a through 2.3.7. This issue has been assigned a CVSS score of 9.6, indicating critical severity. The CVE record was published on 2026-08-20T13:17:27.250Z and was last modified on 2026-08-24T16:40:53.647Z. Security teams and administrators responsible for Easy Elementor Addons installations should b [truncated]

MEDIUM HashThemes CVE published 2026-06-12

CVE-2026-24618

A vulnerability was discovered in HashThemes Hash Elements, a WordPress plugin, which allows for the exposure of sensitive system information to an unauthorized control sphere. This issue, tracked as CVE-2026-24618, has a CVSS score of 4.3 and is classified as MEDIUM severity. The vulnerability enables the retrieval of embedded sensitive data and affects versions of Hash Elements from n/a through 1.5.4.