CVE-2024-7621: Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processwpfeedbackmiscoptions() function in all versions up to, and including, 4.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the plugins settings which can also be leveraged to gain access to the plugin's settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7621?
CVE-2024-7621 is classified as a medium severity vulnerability due to unauthorized data modification risks.
How do I fix CVE-2024-7621?
To fix CVE-2024-7621, update the Atarim plugin to version 4.0.3 or later.
What software is affected by CVE-2024-7621?
CVE-2024-7621 affects all versions of the Atarim plugin for WordPress up to and including 4.0.2.
What can attackers do with CVE-2024-7621?
Attackers can exploit CVE-2024-7621 to make unauthorized modifications to settings and data within the Atarim plugin.
Is there a known exploit for CVE-2024-7621?
As of now, there is no publicly available exploit specifically associated with CVE-2024-7621.