← WordPress Vulnerabilities
WordPress security by component

Atarim

Atarim provides visual website collaboration tools for collecting feedback, annotating pages, and managing client tasks and approvals.

Atarim (atarim-visual-collaboration) is a WordPress plugin with 19 published CVE records in this archive. The latest tracked vulnerability was published Aug 19, 2026; the highest published CVSS base score is 9.8.

Plugin slug: atarim-visual-collaboration

CVE-2026-19942: Atarim Author-level attachment paths permit arbitrary file deletion

Atarim through 5.1.1 lets an Author first invoke the atarim/update-post-field ability to replace an attacker-owned attachment's _wp_attached_file metadata with a directory-traversal path, then invoke atarim/replace-media-file. The AVCF_Abilities_Media::register() replace-media-file callback passes the resolved get_attached_file() path to file deletion without adequate confinement, allowing arbitrary server files such as wp-config.php to be removed and potentially producing remote code execution through the resulting site state.

PublishedAug 19, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for atarim-visual-collaboration
Safe version
Aug 19, 2026 CVE-2026-19942
Atarim Author-level attachment paths permit arbitrary file deletion
Atarim through 5.1.1 lets an Author first invoke the atarim/update-post-field ability to replace an attacker-owned attachment's _wp_attached_file metadata with a directory-traversal path, then invoke atarim/replace-media-file. The AVCF_Abilities_Media::register() replace-media-file callback passes the resolved get_attached_file() path to file deletion without adequate confinement, allowing arbitrary server files such as wp-config.php to be removed and potentially producing remote code execution through the resulting site state.
See mitigation notes
CVE8.1
NVDPending
Mar 13, 2026 CVE-2026-32447
Atarim: A security weakness
Atarim is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 20, 2026 CVE-2025-67993
Atarim: A security weakness
Atarim is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 03, 2026 CVE-2026-25019
Atarim: A security weakness
Atarim is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 06, 2025 CVE-2025-60195
Atarim: Privilege escalation or authentication bypass
Atarim is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Nov 06, 2025 CVE-2025-60188
Atarim: A security weakness
Atarim is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Nov 06, 2025 CVE-2025-60187
Atarim: Dangerous file upload
Atarim is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE4.8
NVDPending
Oct 27, 2025 CVE-2025-62895
Atarim: A security weakness
Atarim is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Feb 25, 2025 CVE-2025-26993
Atarim: Cross-site scripting
Atarim is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Feb 18, 2025 CVE-2025-22657
Atarim: A security weakness
Atarim is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Jan 24, 2025 CVE-2025-24570
Atarim: Cross-site scripting
Atarim is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Nov 01, 2024 CVE-2024-43290
Atarim: A security weakness
Atarim is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 01, 2024 CVE-2024-38771
Atarim: A security weakness
Atarim is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Aug 12, 2024 CVE-2024-7621
Visual Website Collaboration, Feedback & Project Management – Atarim: A security weakness
Visual Website Collaboration, Feedback & Project Management – Atarim is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Jul 22, 2024 CVE-2024-37434
Atarim: Cross-site scripting
Atarim is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8
May 31, 2024 CVE-2024-2793
Visual Website Collaboration, Feedback & Project Management – Atarim: Cross-site scripting
Visual Website Collaboration, Feedback & Project Management – Atarim is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVDPending
May 23, 2024 CVE-2024-2038
Visual Website Collaboration, Feedback & Project Management – Atarim: A security weakness
Visual Website Collaboration, Feedback & Project Management – Atarim is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
Nov 14, 2023 CVE-2023-47544
Atarim Visual Collaboration: Cross-site scripting
Atarim Visual Collaboration is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Sep 04, 2023 CVE-2023-37393
Atarim Visual Collaboration: Cross-site scripting
Atarim Visual Collaboration is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD4.8