
Cloud Vulnerability DB
A community-led vulnerabilities database
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in versions up to and including 3.22.6. This vulnerability was assigned CVE-2024-2038 and was discovered due to the use of hardcoded credentials to authenticate incoming API requests (NVD).
The vulnerability stems from the plugin's implementation of hardcoded credentials for API request authentication. This security flaw exists in the authentication mechanism where all incoming API requests are validated using static credentials, making it possible for unauthenticated attackers to bypass security controls (NVD). The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
The vulnerability allows unauthenticated attackers to perform several unauthorized actions including modifying plugin settings, deleting posts, modifying post titles, and uploading images. This represents a significant risk to the integrity of WordPress sites using the affected plugin versions (NVD).
The vulnerability is highly exploitable as it requires no special privileges or user interaction. An unauthenticated attacker can directly interact with the plugin's API endpoints due to the hardcoded credentials issue (NVD).
Users should update to a version newer than 3.22.6 if available. The vulnerability affects all versions up to and including 3.22.6 (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."