Atarim Plugin Data Loss Vulnerability (CVE-2024-12104) — Medium Severity

The Atarim plugin for WordPress, a popular tool for visual website collaboration and project management, has a notable security vulnerability. This flaw, identified as CVE-2024-12104, could allow malicious actors to delete important project pages and files without needing any authentication.

Essentially, the plugin was missing a crucial security check when handling certain functions, specifically wpf_delete_file. This oversight meant that unauthorized individuals could trigger these functions and cause an unintended loss of your valuable data.

CVE Details

  • Product Name: Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress
  • Published: January 21, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts all versions of the Atarim plugin for WordPress up to, and including, version 4.0.9.

Current Status

The vulnerability has been thoroughly analyzed, and details have been publicly disclosed to ensure users are aware of the risks. Developers have addressed the issue with a security patch.

Severity Level

This vulnerability is rated as Medium severity, with a CVSS score of 5.3. While it doesn’t involve remote code execution or direct system compromise, the potential for unauthorized data deletion could significantly impact website owners and project managers. Losing project pages and files can lead to operational disruptions and potential data recovery costs.

Possible Solutions

The good news is that a fix is available! To protect your WordPress site and project data, it is crucial to update your Atarim plugin immediately.

  • Update to Version 4.1.0 or Later: The developers have released version 4.1.0, which includes a security patch. This update introduces a nonce (a “number used once”) to AJAX calls, specifically for the affected delete functions. This measure significantly enhances security by preventing Cross-Site Request Forgery (CSRF) attacks, ensuring that only authenticated and authorized requests can perform such sensitive actions.

We strongly recommend all users of the Atarim plugin update to version 4.1.0 or newer as soon as possible to mitigate this risk.

References

https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3225314%40atarim-visual-collaboration&new=3225314%40atarim-visual-collaboration&sfp_email=&sfph_mail=

https://www.wordfence.com/threat-intel/vulnerabilities/id/7d40c658-a156-470e-bf93-a1f2ccec9c61?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.