Impact
A missing authorization flaw in the WordPress Atarim Visual Collaboration plugin allows an attacker to bypass the plugin’s configured access control. The issue is classified as CWE-862 (Missing Authorization).
Affected Systems
The vulnerability affects the Atarim Visual Collaboration plugin from Vito Peleg. All releases from the earliest version through 4.3.2 are impacted; any WordPress site using this plugin at version 4.3.2 or earlier is vulnerable.
Risk and Exploitability
The CVSS base score is 4.3, indicating moderate severity, while the EPSS score is under 1%, suggesting low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web-based access to the plugin’s endpoints; this inference is drawn from the nature of the product as a WordPress plugin.
OpenCVE Enrichment