Description
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery.

This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross Site Request Forgery (CWE‑352) in the DevItems HashBar – WordPress Notification Bar plugin. An attacker can construct a request that, if a logged‑in WordPress user visits a crafted link or submits a form, is executed on the victim’s behalf, potentially allowing the attacker to modify or delete content, change settings, or otherwise manipulate the site. The impact is the unauthorized execution of privileged actions with the victim’s permissions.

Affected Systems

This flaw affects all versions of the HashBar – WordPress Notification Bar plugin up to and including 2.0.0. The affected vendor is DevItems; the plugin name is HashBar – WordPress Notification Bar. No specific pre‑2.0.0 versions were reported as vulnerable, but the issue exists through 2.0.0.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. The EPSS score is not available, but the lack of a KEV listing does not reduce the threat that the flaw can be exploited via user interaction. The likely attack vector involves a logged‑in administrator or editor who visits a crafted page containing malicious links or forms hosted on an external site. Based on the description, it is inferred that the attacker only needs the victim to click or otherwise send a request that triggers the vulnerable endpoint, which the plugin fails to protect against CSRF. Therefore, the vulnerability is considered reasonably exploitable in typical web environments.

Generated by OpenCVE AI on August 19, 2026 at 09:02 UTC.

Remediation

Vendor Solution

Update the WordPress HashBar – WordPress Notification Bar Plugin to the latest available version (at least 2.0.1).


OpenCVE Recommended Actions

  • Update the HashBar – WordPress Notification Bar Plugin to the latest version, at least 2.0.1, as supplied by the vendor.
  • If the update cannot be applied immediately, disable the plugin or restrict its activation to trusted administrators only to prevent unauthorized actions.
  • Monitor incoming traffic for unexpected POST or GET requests targeting the plugin’s endpoints and alert on any anomalies.

Generated by OpenCVE AI on August 19, 2026 at 09:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Devitems
Devitems hashbar – Wordpress Notification Bar
Wordpress
Wordpress wordpress
Vendors & Products Devitems
Devitems hashbar – Wordpress Notification Bar
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
Title WordPress HashBar – WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Devitems Hashbar – Wordpress Notification Bar
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-19T15:50:36.779Z

Reserved: 2026-07-27T14:00:08.990Z

Link: CVE-2026-66602

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-18T22:17:25.173

Modified: 2026-08-20T12:49:04.990

Link: CVE-2026-66602

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:31:44Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)