Cross-Site Request Forgery Vulnerability in DevItems HashBar Notification Bar for WordPress
CVE-2026-66602

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2026-66602?

A Cross-Site Request Forgery (CSRF) vulnerability in the DevItems HashBar – WordPress Notification Bar plugin allows attackers to trick users into executing unwanted actions on a website. This can lead to unauthorized changes or access, affecting the integrity of the user's data and the overall security posture of the WordPress site. The vulnerability impacts all versions up to and including 2.0.0, posing significant risks for users who have not updated their installations.

Affected Version(s)

HashBar – WordPress Notification Bar <= 2.0.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Willows | Patchstack Bug Bounty Program
.