PT-2024-18654 · WordPress · Atarim

Lucio Sá

·

Published

2024-05-23

·

Updated

2024-05-24

·

CVE-2024-2038

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress versions up to, and including, 3.22.6
Description The issue is due to the use of hardcoded credentials to authenticate all incoming API requests. This allows unauthenticated attackers to modify plugin settings, delete posts, modify post titles, and upload images.
Recommendations For versions up to, and including, 3.22.6, update to a version that does not use hardcoded credentials for authentication, as this will prevent unauthorized access to the plugin's settings and functionality.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-2038

Affected Products

Atarim