CVE-2026-94117: WordPress HashBar – WordPress Notification Bar plugin <= 2.0.3 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection.
This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DevItems HashBar – WordPress Notification Barto a version that resolves this vulnerability.Fixed in 2.0.4
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires high privileges (PR:H). It is not exploitable by an unauthenticated or low-privileged attacker based on the provided vector.
Can this be exploited remotely without user interaction?
Yes. The attack vector is network-based (AV:N), requires low attack complexity (AC:L), and does not require user interaction (UI:N).
What is the potential impact if exploitation succeeds?
The vulnerability can expose highly sensitive information (C:H) through blind SQL injection and may cause a low availability impact (A:L). The integrity impact is listed as none (I:N).
Which plugin versions are affected?
HashBar – WordPress Notification Bar versions through 2.0.3 are affected. The provided data does not identify a fixed version.