Junglewise Threat Intelligence

CVE-2026-24618: HashThemes Hash Elements sensitive data exposure

CVE-2026-24618 · Severity: medium · CVSS 4.3 · Published 2026-06-12

Vendors: HashThemes.

Executive brief

Hash Elements is a WordPress plugin used to add custom design elements to websites. A security flaw in versions up to 1.5.4 allows logged-in users with low-level permissions to access sensitive system information that should be restricted. This could lead to the exposure of internal configuration details, which attackers might use to plan more advanced attacks against the site.

Technical details

The Hash Elements plugin for WordPress (versions up to 1.5.4) is vulnerable to CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere. The vulnerability allows an authenticated attacker with 'Contributor' level privileges or higher to retrieve sensitive embedded data through the plugin's functionality. This occurs because the application does not properly restrict access to certain system-level information within its control sphere. An attacker can exploit this over the network without user interaction to gain insights into the system's internal state or configuration. The issue is resolved in version 1.5.5.

Affected products

  • HashThemes Hash Elements n/a through 1.5.4

Timeline

  • 2025-12-12: other: Reported by researcher theviper17
  • 2026-06-12: patched: Version 1.5.5 released
  • 2026-06-12: disclosed: Public advisory published by Patchstack

References