CVE-2026-24618: WordPress Hash Elements plugin <= 1.5.4 - Sensitive Data Exposure vulnerability
Published Jun 12, 2026
·Updated
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HashThemes Hash Elements allows Retrieve Embedded Sensitive Data.
This issue affects Hash Elements: from n/a through 1.5.4.
Affected Software
1 affected component
HashThemes Hash Elements<=1.5.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Hash Elements pluginto a version that resolves this vulnerability.Fixed in 1.5.5
Event History
Jun 12, 2026
CVE Published
via MITRE·08:46 PM
Data Sourced
via MITRE·08:46 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-24618?
CVE-2026-24618 has a medium severity rating of 4.3.
2
How do I fix CVE-2026-24618?
To fix CVE-2026-24618, update the WordPress Hash Elements Plugin to at least version 1.5.5.
3
What type of vulnerability is CVE-2026-24618?
CVE-2026-24618 is a Sensitive Data Exposure vulnerability.
4
Which versions of Hash Elements are affected by CVE-2026-24618?
CVE-2026-24618 affects Hash Elements versions from n/a up to 1.5.4.
5
What kind of information is at risk with CVE-2026-24618?
CVE-2026-24618 can expose sensitive system information to an unauthorized control sphere.