Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: from n/a through 1.5.4.
History

Sat, 13 Jun 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Hashthemes
Hashthemes hash Elements
Wordpress
Wordpress wordpress
Vendors & Products Hashthemes
Hashthemes hash Elements
Wordpress
Wordpress wordpress

Fri, 12 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data. This issue affects Hash Elements: from n/a through 1.5.4.
Title WordPress Hash Elements plugin <= 1.5.4 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published: 2026-06-12T20:46:18.717Z

Updated: 2026-06-13T03:35:17.571Z

Reserved: 2026-01-23T12:32:24.372Z

Link: CVE-2026-24618

cve-icon Vulnrichment

Updated: 2026-06-13T03:35:13.333Z

cve-icon NVD

Status : Deferred

Published: 2026-06-12T21:16:21.153

Modified: 2026-06-15T20:42:32.707

Link: CVE-2026-24618

cve-icon Redhat

No data.