Cross-Site Request Forgery Vulnerability in DevItems HashBar Notification Bar for WordPress
CVE-2026-66602
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-66602?
A Cross-Site Request Forgery (CSRF) vulnerability in the DevItems HashBar β WordPress Notification Bar plugin allows attackers to trick users into executing unwanted actions on a website. This can lead to unauthorized changes or access, affecting the integrity of the user's data and the overall security posture of the WordPress site. The vulnerability impacts all versions up to and including 2.0.0, posing significant risks for users who have not updated their installations.
Affected Version(s)
HashBar β WordPress Notification Bar <= 2.0.0