PT-2024-18654 · WordPress · Atarim

·

CVE-2024-2038

·

Published

2024-05-23

·

Updated

2024-05-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress versions up to, and including, 3.22.6
Description The issue is due to the use of hardcoded credentials to authenticate all incoming API requests. This allows unauthenticated attackers to modify plugin settings, delete posts, modify post titles, and upload images.
Recommendations For versions up to, and including, 3.22.6, update to a version that does not use hardcoded credentials for authentication, as this will prevent unauthorized access to the plugin's settings and functionality.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2038

Affected Products

Atarim