Vulnerability Details CVE-2024-12104
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes it possible for unauthenticated attackers to delete project pages and files. CVE-2025-22657 may be a duplicate of this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.4%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2024-12104
-
cpe:2.3:a:atarim:atarim:-
-
cpe:2.3:a:atarim:atarim:3.10
-
cpe:2.3:a:atarim:atarim:3.11
-
cpe:2.3:a:atarim:atarim:3.12
-
cpe:2.3:a:atarim:atarim:3.13
-
cpe:2.3:a:atarim:atarim:3.14
-
cpe:2.3:a:atarim:atarim:3.15
-
cpe:2.3:a:atarim:atarim:3.16
-
cpe:2.3:a:atarim:atarim:3.17
-
cpe:2.3:a:atarim:atarim:3.18
-
cpe:2.3:a:atarim:atarim:3.19
-
cpe:2.3:a:atarim:atarim:3.2
-
cpe:2.3:a:atarim:atarim:3.2.1
-
cpe:2.3:a:atarim:atarim:3.22
-
cpe:2.3:a:atarim:atarim:3.22.2
-
cpe:2.3:a:atarim:atarim:3.22.3
-
cpe:2.3:a:atarim:atarim:3.22.4
-
cpe:2.3:a:atarim:atarim:3.22.6
-
cpe:2.3:a:atarim:atarim:3.3
-
cpe:2.3:a:atarim:atarim:3.3.1
-
cpe:2.3:a:atarim:atarim:3.3.2
-
cpe:2.3:a:atarim:atarim:3.3.2.1
-
cpe:2.3:a:atarim:atarim:3.3.2.2
-
cpe:2.3:a:atarim:atarim:3.3.3
-
cpe:2.3:a:atarim:atarim:3.30
-
cpe:2.3:a:atarim:atarim:3.31
-
cpe:2.3:a:atarim:atarim:3.32
-
cpe:2.3:a:atarim:atarim:3.4
-
cpe:2.3:a:atarim:atarim:3.4.1
-
cpe:2.3:a:atarim:atarim:3.4.3
-
cpe:2.3:a:atarim:atarim:3.4.4
-
cpe:2.3:a:atarim:atarim:3.5
-
cpe:2.3:a:atarim:atarim:3.5.1
-
cpe:2.3:a:atarim:atarim:3.6
-
cpe:2.3:a:atarim:atarim:3.6.1
-
cpe:2.3:a:atarim:atarim:3.7
-
cpe:2.3:a:atarim:atarim:3.8
-
cpe:2.3:a:atarim:atarim:3.9
-
cpe:2.3:a:atarim:atarim:3.9.1
-
cpe:2.3:a:atarim:atarim:3.9.2
-
cpe:2.3:a:atarim:atarim:3.9.3
-
cpe:2.3:a:atarim:atarim:3.9.4
-
cpe:2.3:a:atarim:atarim:3.9.6
-
cpe:2.3:a:atarim:atarim:4.0
-
cpe:2.3:a:atarim:atarim:4.0.1