SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-66602

HIGH · CVSS 8.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The DevItems HashBar – WordPress Notification Bar plugin is vulnerable to a Cross-Site Request Forgery (CSRF) attack, which could allow an attacker to perform unauthorized actions on behalf of authenticated users. This high-severity vulnerability impacts versions up to 2.0.0 and should be prioritized by all WordPress site administrators using this plugin to mitigate potential exploitation risks.

CVE
CVE-2026-66602
Severity
HIGH
CVSS
8.8
EPSS
0.15%
WordPress

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.