WordPress Plugin Vulnerabilities

Atarim < 3.30 - Unauthenticated Settings Update, Post Deletion etc

Description

The plugin is vulnerable to unauthorized access due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticated attackers to modify plugin settings, delete posts, modify post titles, and upload images.

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Lucio Sá
Verified
No

Timeline

Publicly Published
2024-05-22 (about 2 years ago)
Added
2024-05-23 (about 2 years ago)
Last Updated
2024-05-23 (about 2 years ago)

Other