The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.22.6. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to modify plugin settings, delete posts, modify post titles, and upload images.
History

Fri, 27 Feb 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Atarim
Atarim visual Collaboration
CPEs cpe:2.3:a:atarim:visual_collaboration:*:*:*:*:*:wordpress:*:*
Vendors & Products Atarim
Atarim visual Collaboration
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-05-23T06:46:02.833Z

Updated: 2024-08-01T18:56:22.827Z

Reserved: 2024-02-29T20:32:44.783Z

Link: CVE-2024-2038

cve-icon Vulnrichment

Updated: 2024-08-01T18:56:22.827Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-23T07:15:08.013

Modified: 2024-11-21T09:08:54.393

Link: CVE-2024-2038

cve-icon Redhat

No data.