Vulnerabilities > CVE-2024-12104 - Missing Authorization vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
atarim
CWE-862

Summary

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes it possible for unauthenticated attackers to delete project pages and files.

Vulnerable Configurations

Part Description Count
Application
Atarim
1

Common Weakness Enumeration (CWE)