Impact
A missing authorization check in Vito Peleg’s Atarim WordPress plugin allows an attacker to delete arbitrary content. Classified as CWE‑862, the flaw undermines data integrity and availability by permitting unauthorized users to remove posts, pages or other site elements. The advisory indicates that the flaw arises from incorrectly configured access control security levels applied to the plugin’s content‑deletion functionality.
Affected Systems
The vulnerability affects the Atarim visual‑collaboration plugin, version 4.0.9 and all earlier releases. No additional product or version details have been provided.
Risk and Exploitability
The CVSS score of 7.5 marks the issue as high risk. An EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. If an attacker can reach the WordPress site, they can exploit the missing authorization flaw by sending a crafted HTTP request to the plugin’s deletion endpoint with the target content identifier, thereby causing data loss because proper authorization checks are missing.
OpenCVE Enrichment
EUVD