Impact
This vulnerability is a missing authorization flaw in the Atarim Visual Collaboration plugin for WordPress. It allows an attacker to perform actions that should be restricted to certain users, potentially leading to unauthorized modifications of content, settings, or other resources managed by the plugin. The weakness is classified as CWE‑862 missing authorization.
Affected Systems
The flaw affects the Atarim plugin developed by Vito Peleg, versions 4.3.1 and earlier. Users running WordPress sites with Atarim installed at these versions are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability that this vulnerability will be exploited at the time of this analysis. It is not listed in the CISA KEV catalog. The likely attack vector is via the plugin’s web interface or API accessed through a web browser or HTTP client. The description does not specify authentication requirements, so it is unclear whether an unauthenticated user can also exploit the flaw.
OpenCVE Enrichment