CVE-2024-2038
WordPress vulnerability analysis and mitigation

Overview

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in versions up to and including 3.22.6. This vulnerability was assigned CVE-2024-2038 and was discovered due to the use of hardcoded credentials to authenticate incoming API requests (NVD).

Technical details

The vulnerability stems from the plugin's implementation of hardcoded credentials for API request authentication. This security flaw exists in the authentication mechanism where all incoming API requests are validated using static credentials, making it possible for unauthenticated attackers to bypass security controls (NVD). The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

Impact

The vulnerability allows unauthenticated attackers to perform several unauthorized actions including modifying plugin settings, deleting posts, modifying post titles, and uploading images. This represents a significant risk to the integrity of WordPress sites using the affected plugin versions (NVD).

Exploitability

The vulnerability is highly exploitable as it requires no special privileges or user interaction. An unauthenticated attacker can directly interact with the plugin's API endpoints due to the hardcoded credentials issue (NVD).

Mitigation and workarounds

Users should update to a version newer than 3.22.6 if available. The vulnerability affects all versions up to and including 3.22.6 (NVD).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-65640HIGH8.8
  • wordpress
NoYesAug 17, 2026
CVE-2026-11801HIGH7.5
  • wpadverts
NoYesAug 18, 2026
CVE-2026-13700MEDIUM5.9
  • wooms
NoNoAug 17, 2026
CVE-2026-14832MEDIUM5.3
  • shopsmart-loyalty-for-woocommerce
NoNoAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management