HashBar – Announcement, Notification Bar & Popup Campaign <= 2.0.0 - Cross-Site Request Forgery
medium
The HashBar – Announcement, Notification Bar & Popup Campaign plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized...
- CVSS:
- 4.3
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.1
- Disclosed:
- Aug 18, 2026
CVE-2026-66602 on NVD →
HashBar – WordPress Notification Bar <= 1.4.1 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The HashBar – WordPress Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to, and including 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and abov...
- CVSS:
- 6.4
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.2
- Disclosed:
- Dec 26, 2023
CVE-2023-51372 on NVD →
HashBar – WordPress Notification Bar <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The HashBar – WordPress Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with c...
- CVSS:
- 6.4
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.6
- Disclosed:
- Dec 27, 2022
CVE-2022-4650 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database