Impact
The vulnerability is an insertion of sensitive information into data sent out of the system. Labeled as CWE‑201, this embedded sensitive data that may include personal or credential information, thereby compromising confidentiality.
Affected Systems
The issue affects Vito Peleg’s Atarim visual collaboration plugin for WordPress for all releases up to and including 4.2.1. that has any of these affected plugin versions is at risk.
Risk and Exploitability
The CVSS score of 7.5 signals high severity, while the EPSS score of 3% indicates a low but non‑zero likelihood of exploitation in the wild. Based on the description, the likely attack vector is remote via HTTP requests to the site, as the vulnerability involves data sent out of the system. The vulnerability is not listed in the CISA KEV catalog, but the potential for sensitive data exposure warrants prompt remediation.
OpenCVE Enrichment