What the vulnerability does
01Description
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.22.6. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to modify plugin settings, delete posts, modify post titles, and upload images.
Explanation of Vulnerability in Simple Terms
02Summary
Atarim – Visual Feedback, Review & AI Collaboration versions up to 3.22.6 contain a use of hardcoded credentials vulnerability. An attacker with network access can exploit this flaw to gain unauthorized access to the application without authentication. The vulnerability allows attackers to bypass security controls and access sensitive functionality or data.
What an attacker can do
03Attacker Capabilities
Gain unauthorized access to the application using hardcoded credentials without authentication.
Potential impact on your site
04Site Impact
Attackers can access your Atarim installation and its data without logging in, potentially compromising feedback, reviews, and collaboration data.
Conditions required to exploit
05Prerequisites
Network access to the affected Atarim installation; no authentication or user interaction required.
Key dates
06Disclosure timeline
May 23, 2024
CVE published
April 8, 2026
Record updated