Executive brief
The Hello Bar Popup Builder plugin for WordPress, used to create notification bars and popups, is vulnerable to a security flaw that allows attackers to inject malicious scripts into a website. An attacker with basic contributor-level access could use this to redirect visitors to malicious sites or steal sensitive session information. This risk is realized when a site administrator or visitor interacts with a specially crafted link or page created by the attacker.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the telepathy Hello Bar Popup Builder plugin (hellobar) for WordPress due to improper neutralization of input during web page generation. The flaw allows an attacker with 'Contributor' or higher privileges to inject malicious JavaScript payloads that execute in the context of a victim's browser. Exploitation requires user interaction, such as a privileged user viewing a specific page or clicking a crafted link. The vulnerability is addressed in version 1.5.2.
Affected products
- telepathy Hello Bar Popup Builder <= 1.5.1
Timeline
- 2026-01-19: other: Vulnerability reported by researcher
- 2026-02-18: advisory: Initial advisory published by Patchstack
- 2026-04-08: disclosed: CVE published to NVD
- 2026-02-18: patched: Version 1.5.2 released to address the issue