Cross-Site Scripting Vulnerability in HashThemes Hash Elements
CVE-2025-22296
6.5MEDIUM
What is CVE-2025-22296?
An input validation flaw exists in HashThemes Hash Elements that allows attackers to inject arbitrary web scripts via user inputs, leading to potential unauthorized access and user session hijacking. This vulnerability impacts all versions from n/a through 1.4.9, posing a risk to websites utilizing this WordPress plugin.
Affected Version(s)
Hash Elements 0 <= 1.5.0