Executive brief
HashBar is a WordPress plugin that displays notification bars on websites. This vulnerability allows attackers to execute blind SQL injection attacks, potentially reading, modifying, or deleting the entire website database including user accounts and private data. Exploitation requires administrator privileges and is unlikely to occur in the wild.
Technical details
SQL injection vulnerability in the HashBar WordPress plugin allows authenticated administrators to inject arbitrary SQL commands through unspecified input. The vulnerability is classified as blind SQL injection, meaning attackers cannot directly see query results but can infer data through time-based or boolean-based techniques. A patch is available in version 2.0.4.
Affected products
- DevItems HashBar WordPress Notification Bar through 2.0.3
Timeline
- 2026-09-21: disclosed
- 2026-09-22: advisory
- 2026-09-21: patched: Version 2.0.4 available