CVE-2026-66602: WordPress HashBar – WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery.
This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress HashBar – WordPress Notification Barto a version that resolves this vulnerability.Fixed in 2.0.1
Event History
Frequently Asked Questions
Which installations are affected?
Sites using HashBar – WordPress Notification Bar version 2.0.0 or an earlier affected version are exposed. The affected range is stated as through 2.0.0, with no lower bound provided.
What does an attacker need to exploit this issue?
The CVSS vector indicates network-reachable exploitation with low attack complexity, no attacker privileges required, and user interaction required. This is consistent with a CSRF attack requiring a victim to interact with attacker-controlled content while authenticated.
What should administrators do if they use the affected plugin?
The available information does not state whether the plugin is vulnerable in its default configuration or identify a temporary mitigation. Update to a version newer than 2.0.0 when one is available.