CVE Tools

Hashthemes

4 CVEs tracked since 2024. Since Dec 2024, none of them reached CISA KEV.

Hashthemes CVEs per month

Dec 2024 to Dec 2024. Point at a month, or focus the strip and use the arrow keys.
Hashthemes CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-1240

Products

The products that kept showing up in Hashthemes's monthly top three, with their CVEs summed over those months.

  1. Hash Form11 month
  2. Hash Form – Drag & Drop Form Builder11 month
  3. Square11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Hashthemes.

  1. CVE-2026-81780WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability10.0
  2. CVE-2026-78292WordPress Hash Form plugin <= 1.4.1 - PHP Object Injection vulnerability9.8
  3. CVE-2026-78280WordPress Hash Form plugin <= 1.4.0 - Cross Site Request Forgery (CSRF) vulnerability4.3
  4. CVE-2026-28164WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery (CSRF) vulnerability9.6
  5. CVE-2026-65483WordPress HashThemes Demo Importer plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability5.9
  6. CVE-2026-24618WordPress Hash Elements plugin <= 1.5.4 - Sensitive Data Exposure vulnerability4.3
  7. CVE-2026-5077Total <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title in Blog Section Image alt Attribute5.4
  8. CVE-2026-6370WordPress Mini Ajax Cart for WooCommerce plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability5.9
  9. CVE-2025-9045Easy Elementor Addons <= 2.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting6.4
  10. CVE-2025-58973WordPress Easy Elementor Addons Plugin <= 2.2.8 - Local File Inclusion Vulnerability7.5
  11. CVE-2025-59561WordPress Smart Blocks Plugin <= 2.4 - Broken Access Control Vulnerability4.3
  12. CVE-2025-54712WordPress Easy Elementor Addons Plugin <= 2.2.7 - Broken Access Control Vulnerability4.3
  13. CVE-2025-54704WordPress Easy Elementor Addons plugin <= 2.2.6 - Cross Site Scripting (XSS) Vulnerability6.5
  14. CVE-2025-48295WordPress Easy Elementor Addons plugin <= 2.2.5 - Cross Site Scripting (XSS) Vulnerability6.5
  15. CVE-2025-47468WordPress Hash Form plugin <= 1.2.8 - Cross Site Request Forgery (CSRF) Vulnerability4.3

The record

Peak rank
#168 in Dec 2024
Busiest month shown
Dec 2024, 4 CVEs
Months with a KEV entry
0 since Dec 2024
Monthly snapshots
1 since 2024
Hashthemes's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store