Impact
The vulnerability is a Cross Site Request Forgery (CWE‑352) in the DevItems HashBar – WordPress Notification Bar plugin. An attacker can construct a request that, if a logged‑in WordPress user visits a crafted link or submits a form, is executed on the victim’s behalf, potentially allowing the attacker to modify or delete content, change settings, or otherwise manipulate the site. The impact is the unauthorized execution of privileged actions with the victim’s permissions.
Affected Systems
This flaw affects all versions of the HashBar – WordPress Notification Bar plugin up to and including 2.0.0. The affected vendor is DevItems; the plugin name is HashBar – WordPress Notification Bar. No specific pre‑2.0.0 versions were reported as vulnerable, but the issue exists through 2.0.0.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, but the lack of a KEV listing does not reduce the threat that the flaw can be exploited via user interaction. The likely attack vector involves a logged‑in administrator or editor who visits a crafted page containing malicious links or forms hosted on an external site. Based on the description, it is inferred that the attacker only needs the victim to click or otherwise send a request that triggers the vulnerable endpoint, which the plugin fails to protect against CSRF. Therefore, the vulnerability is considered reasonably exploitable in typical web environments.
OpenCVE Enrichment