The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes it possible for unauthenticated attackers to delete project pages and files.
References
Configurations
Configuration 1 (hide)
|
History
31 Jan 2025, 20:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3225314%40atarim-visual-collaboration&new=3225314%40atarim-visual-collaboration&sfp_email=&sfph_mail= - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/7d40c658-a156-470e-bf93-a1f2ccec9c61?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:atarim:visual_website_collaboration\,_feedback_\&_project_management:*:*:*:*:*:wordpress:*:* | |
Summary |
|
|
First Time |
Atarim visual Website Collaboration\, Feedback \& Project Management
Atarim |
21 Jan 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-21 10:15
Updated : 2025-01-31 20:17
NVD link : CVE-2024-12104
Mitre link : CVE-2024-12104
CVE.ORG link : CVE-2024-12104
JSON object : View
Products Affected
atarim
- visual_website_collaboration\,_feedback_\&_project_management
CWE
CWE-862
Missing Authorization