The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes it possible for unauthenticated attackers to delete project pages and files.
History

Fri, 31 Jan 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Atarim
Atarim visual Website Collaboration\, Feedback \& Project Management
CPEs cpe:2.3:a:atarim:visual_website_collaboration\,_feedback_\&_project_management:*:*:*:*:*:wordpress:*:*
Vendors & Products Atarim
Atarim visual Website Collaboration\, Feedback \& Project Management

Tue, 21 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 09:30:00 +0000

Type Values Removed Values Added
Description The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes it possible for unauthenticated attackers to delete project pages and files.
Title Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-01-21T15:19:39.746Z

Reserved: 2024-12-03T15:45:59.027Z

Link: CVE-2024-12104

cve-icon Vulnrichment

Updated: 2025-01-21T15:19:35.072Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-21T10:15:07.590

Modified: 2025-01-31T20:17:45.907

Link: CVE-2024-12104

cve-icon Redhat

No data.