Impact
The vulnerability is an Incorrect Privilege Assignment flaw that permits a user with lower privileges to gain higher access rights within the Atarim Visual Collaboration plugin. An attacker exploiting this weakness could elevate privileges, potentially allowing them to modify plugin settings, view or manipulate protected content, or gain administrative control over the WordPress site. The flaw is a classic example of CWE‑266: Improper Privilege Management.
Affected Systems
Vendor Vito Peleg offers the Atarim Visual Collaboration plugin. All installations of the plugin from the initial release through version 4.2.1 are affected. Upgrading beyond 4.2.1 removes the flaw.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity. The EPSS score of less than 1% suggests a low probability of exploitation at present, yet the vulnerability remains publicly disclosed and listed in KEV as not yet targeted. The most probable attack vector is through the plugin’s administrative interface, which can be accessed by any authenticated user who has the plugin enabled. Anyone who can install or activate Atarim without proper privilege checks can exploit the bug to gain elevated rights.
OpenCVE Enrichment