OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94117

HIGH · CVSS 7.6 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The HashBar – WordPress Notification Bar plugin is vulnerable to a SQL Injection flaw that allows attackers to execute arbitrary SQL commands, potentially compromising the database. This vulnerability impacts versions up to 2.0.3 and poses a significant risk to WordPress sites using this plugin, making it essential for site administrators and developers to prioritize immediate updates or mitigation strategies.

CVE
CVE-2026-94117
Severity
HIGH
CVSS
7.6
EPSS
0.38%
WordPress

Original NVD Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3.