The Atarim plugin for WordPress, a popular tool for visual website collaboration and project management, has a notable security vulnerability. This flaw, identified as CVE-2024-12104, could allow malicious actors to delete important project pages and files without needing any authentication.
Essentially, the plugin was missing a crucial security check when handling certain functions, specifically wpf_delete_file. This oversight meant that unauthorized individuals could trigger these functions and cause an unintended loss of your valuable data.
CVE Details
- Product Name: Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress
- Published: January 21, 2025
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts all versions of the Atarim plugin for WordPress up to, and including, version 4.0.9.
Current Status
The vulnerability has been thoroughly analyzed, and details have been publicly disclosed to ensure users are aware of the risks. Developers have addressed the issue with a security patch.
Severity Level
This vulnerability is rated as Medium severity, with a CVSS score of 5.3. While it doesn’t involve remote code execution or direct system compromise, the potential for unauthorized data deletion could significantly impact website owners and project managers. Losing project pages and files can lead to operational disruptions and potential data recovery costs.
Possible Solutions
The good news is that a fix is available! To protect your WordPress site and project data, it is crucial to update your Atarim plugin immediately.
- Update to Version 4.1.0 or Later: The developers have released version 4.1.0, which includes a security patch. This update introduces a nonce (a “number used once”) to AJAX calls, specifically for the affected delete functions. This measure significantly enhances security by preventing Cross-Site Request Forgery (CSRF) attacks, ensuring that only authenticated and authorized requests can perform such sensitive actions.
We strongly recommend all users of the Atarim plugin update to version 4.1.0 or newer as soon as possible to mitigate this risk.
References
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3225314%40atarim-visual-collaboration&new=3225314%40atarim-visual-collaboration&sfp_email=&sfph_mail=
https://www.wordfence.com/threat-intel/vulnerabilities/id/7d40c658-a156-470e-bf93-a1f2ccec9c61?source=cve


