Atarim <= 5.1.1 - Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta
high
The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the AVCF_Abilities_Media::register (replace-media-file execute_callback) function in all versions up to, and includi...
- CVSS:
- 8.1
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.2
- Disclosed:
- Aug 18, 2026
CVE-2026-19942 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] <= 4.3.2 (unfixed)
unknown
[en] Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.3.2.
- Affected:
- up to 4.3.2
- Fix:
- No patched version reported
- Disclosed:
- Mar 13, 2026
CVE-2026-32447 on NVD →
Atarim <= 4.3.2 - Missing Authorization
medium
The Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.3.2
- Fixed in:
- 4.3.3
- Disclosed:
- Mar 8, 2026
CVE-2026-32447 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] <= 4.2.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.2.1.
- Affected:
- up to 4.2.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2026
CVE-2025-67993 on NVD →
Atarim <= 4.2.1 - Missing Authorization
medium
The Visual Feedback, Review & AI Collaboration Tool For WordPress – Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Feb 9, 2026
CVE-2025-67993 on NVD →
Atarim <= 4.0.9 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
medium
The Atarim – Visual Feedback, Review & AI Collaboration plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.0.9. This makes it possible for unauthenticated attackers to delete arbitrary posts.
- CVSS:
- 5.3
- Affected:
- up to 4.0.9
- Fixed in:
- 4.1.0
- Disclosed:
- Feb 3, 2026
CVE-2025-22657 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] <= 4.3.1 (unfixed)
unknown
[en] Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.3.1.
- Affected:
- up to 4.3.1
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-25019 on NVD →
Atarim <= 4.3.1 - Missing Authorization
medium
The Visual Feedback, Review & AI Collaboration Tool For WordPress – Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.3.1
- Fixed in:
- 4.3.2
- Disclosed:
- Jan 30, 2026
CVE-2026-25019 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] <= 4.2 (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Using Malicious Files.This issue affects Atarim: from n/a through <= 4.2.
- Affected:
- up to 4.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-60187 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] <= 4.2 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Privilege Escalation.This issue affects Atarim: from n/a through <= 4.2.
- Affected:
- up to 4.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-60195 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] <= 4.2 (unfixed)
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Data.This issue affects Atarim: from n/a through <= 4.2.
- Affected:
- up to 4.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-60188 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] <= 4.2 (unfixed)
unknown
[en] Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Data.This issue affects Atarim: from n/a through <= 4.2.
- Affected:
- up to 4.2
- Fix:
- No patched version reported
- Disclosed:
- Oct 27, 2025
CVE-2025-62895 on NVD →
Atarim <= 4.2.1 - Unauthenticated Information Exposure
medium
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Sep 15, 2025
CVE-2025-62895 on NVD →
Atarim <= 4.2.1 - Unauthenticated Arbitrary File Upload
critical
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's ser...
- CVSS:
- 9.8
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Jul 29, 2025
CVE-2025-60187 on NVD →
Atarim <= 4.2.1 - Unauthenticated Information Exposure
medium
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Jul 29, 2025
CVE-2025-60188 on NVD →
Atarim <= 4.2.1 - Unauthenticated Privilege Escalation
critical
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- Jul 27, 2025
CVE-2025-60195 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 4.1.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vito Peleg Atarim allows Reflected XSS. This issue affects Atarim: from n/a through 4.1.0.
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 25, 2025
CVE-2025-26993 on NVD →
Atarim <= 4.1.0 - Reflected Cross-Site Scripting
medium
The Atarim plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- CVSS:
- 6.1
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.1
- Disclosed:
- Feb 23, 2025
CVE-2025-26993 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 4.1.0
unknown
[en] Missing Authorization vulnerability in Vito Peleg Atarim allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Atarim: from n/a through 4.0.9.
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Feb 18, 2025
CVE-2025-22657 on NVD →
Atarim <= 4.0.8 - Unauthenticated Stored Cross-Site Scripting
high
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web...
- CVSS:
- 7.2
- Affected:
- up to 4.0.8
- Fixed in:
- 4.0.9
- Disclosed:
- Jan 24, 2025
CVE-2025-24570 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 4.0.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atarim Atarim allows Stored XSS. This issue affects Atarim: from n/a through 4.0.8.
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Jan 24, 2025
CVE-2025-24570 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 4.1.0
unknown
[en] The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes it possible for unauthenticated att...
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Jan 21, 2025
CVE-2024-12104 on NVD →
Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion
medium
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes it possible for unauthenticated attacker...
- CVSS:
- 5.3
- Affected:
- up to 4.0.9
- Fixed in:
- 4.1.0
- Disclosed:
- Jan 20, 2025
CVE-2024-12104 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 4.0.1
unknown
[en] Missing Authorization vulnerability in Atarim allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Atarim: from n/a through 4.0.
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.1
- Disclosed:
- Nov 1, 2024
CVE-2024-38771 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 4.0.2
unknown
[en] Missing Authorization vulnerability in Atarim allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Atarim: from n/a through 4.0.1.
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Nov 1, 2024
CVE-2024-43290 on NVD →
Atarim <= 4.0.1 - Missing Authorization via remove_feedbacktool_notice()
medium
The Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_feedbacktool_notice() function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to dismiss feedback tool notice.
- CVSS:
- 5.3
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 16, 2024
CVE-2024-43290 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 4.0.3
unknown
[en] The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_wpfeedback_misc_options() function in all versions up to, and including, 4.0.2. This makes it possible for authenticated...
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- Aug 10, 2024
CVE-2024-7621 on NVD →
Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update
medium
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_wpfeedback_misc_options() function in all versions up to, and including, 4.0.2. This makes it possible for authenticated attac...
- CVSS:
- 5.4
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.3
- Disclosed:
- Aug 9, 2024
CVE-2024-7621 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 3.32
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Atarim allows Stored XSS.This issue affects Atarim: from n/a through 3.31.
- Affected:
- up to 3.32
- Fixed in:
- 3.32
- Disclosed:
- Jul 22, 2024
CVE-2024-37434 on NVD →
Atarim <= 4.0 - Missing Authorization
medium
The Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 4.0
- Fixed in:
- 4.0.1
- Disclosed:
- Jul 19, 2024
CVE-2024-38771 on NVD →
Atarim <= 3.31 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with ad...
- CVSS:
- 4.4
- Affected:
- up to 3.31
- Fixed in:
- 3.32
- Disclosed:
- Jun 28, 2024
CVE-2024-37434 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 3.31
unknown
[en] The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via comments in all versions up to, and including, 3.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inje...
- Affected:
- up to 3.31
- Fixed in:
- 3.31
- Disclosed:
- May 31, 2024
CVE-2024-2793 on NVD →
Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.30 - Unauthenticated Stored Cross-Site Scripting
high
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via comments in all versions up to, and including, 3.30 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- CVSS:
- 7.2
- Affected:
- up to 3.30
- Fixed in:
- 3.31
- Disclosed:
- May 30, 2024
CVE-2024-2793 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 3.30
unknown
[en] The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.22.6. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated...
- Affected:
- up to 3.30
- Fixed in:
- 3.30
- Disclosed:
- May 23, 2024
CVE-2024-2038 on NVD →
Visual Website Collaboration, Feedback & Project Management – Atarim <= 3.22.6 - Hardcoded Credentials
high
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.22.6. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attac...
- CVSS:
- 7.5
- Affected:
- up to 3.22.6
- Fixed in:
- 3.30
- Disclosed:
- May 22, 2024
CVE-2024-2038 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 3.13
unknown
[en] Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.12 versions.
- Affected:
- up to 3.13
- Fixed in:
- 3.13
- Disclosed:
- Nov 14, 2023
CVE-2023-47544 on NVD →
Atarim <= 3.12 - Unauthenticated Cross-Site Scripting
medium
The Atarim plugin for WordPress is vulnerable to Cross-Site Scripting via the new_task parameter in versions up to, and including, 3.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u...
- CVSS:
- 6.1
- Affected:
- up to 3.12
- Fixed in:
- 3.13
- Disclosed:
- Nov 7, 2023
CVE-2023-47544 on NVD →
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 3.9.4
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3 versions.
- Affected:
- up to 3.9.4
- Fixed in:
- 3.9.4
- Disclosed:
- Sep 4, 2023
CVE-2023-37393 on NVD →
Atarim <= 3.9.3 - Reflected Cross-Site Scripting
medium
The Atarim plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_graphics_excerpt' parameter in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 3.9.3
- Fixed in:
- 3.9.4
- Disclosed:
- Aug 10, 2023
CVE-2023-37393 on NVD →
Atarim - Client Interface <= 3.9.1 - Missing Authorization via AJAX actions
critical
The Atarim - Client Interface plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the avc_send_invitations and avc_delete_invitations functions in versions up to, and including, 3.9.1. This makes it possible for unauthenticated attackers to delete arbitrary accou...
- CVSS:
- 9.1
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Jul 7, 2023
Atarim – Visual Feedback, Review & AI Collaboration [atarim-visual-collaboration] < 3.9.2
unknown
The Atarim - Client Interface plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the avc_send_invitations and avc_delete_invitations functions in versions up to, and including, 3.9.1. This makes it possible for unauthenticated attackers to delete arbitrary accou...
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Jul 7, 2023