CVE-2025-26993: WordPress Visual Website Collaboration Atarim plugin <= 4.1.0 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Reflected XSS.This issue affects Atarim: from n/a through <= 4.1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26993?
CVE-2025-26993 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS).
How do I fix CVE-2025-26993?
To mitigate CVE-2025-26993, update Atarim to version 4.1.1 or later where the vulnerability has been patched.
What systems are affected by CVE-2025-26993?
CVE-2025-26993 affects Atarim versions from n/a through 4.1.0.
What can an attacker do with CVE-2025-26993?
An attacker can exploit CVE-2025-26993 to execute arbitrary scripts in the context of the user's browser, potentially stealing sensitive information.
Is CVE-2025-26993 specific to any platforms?
CVE-2025-26993 primarily affects the Atarim plugin for WordPress, specifically the Visual Website Collaboration tool.