Plugin Vulnerability Hub
Plugin 19 known issues Latest disclosed Mar 08, 2026

Atarim – Visual Feedback, Review & AI Collaboration Vulnerabilities

Review known vulnerability records for the WordPress plugin Atarim – Visual Feedback, Review & AI Collaboration (`atarim-visual-collaboration`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-32447, CVE-2025-67993 and CVE-2026-25019, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
19
High or Critical
6
Patch Coverage
100%
Last Updated
Apr 15, 2026
Priority CVE Quick Links

Fast paths into Atarim – Visual Feedback, Review & AI Collaboration CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
18
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Atarim – Visual Feedback, Review & AI Collaboration so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
19 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
3 critical and 3 high severity findings.
Recent CVEs
CVE-2026-32447, CVE-2025-67993 and CVE-2026-25019
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Atarim – Visual Feedback, Review & AI Collaboration

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-32447
CVE-2026-32447: Atarim <= 4.3.2 - Missing Authorization

The Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized act...

Published
Mar 08, 2026
Patched Release
4.3.3
Affected Versions
Versions up to 4.3.2
Next Step
Update to 4.3.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-67993
CVE-2025-67993: Atarim <= 4.2.1 - Missing Authorization

The Visual Feedback, Review & AI Collaboration Tool For WordPress – Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers t...

Published
Feb 09, 2026
Patched Release
4.2.2
Affected Versions
Versions up to 4.2.1
Next Step
Update to 4.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-25019
CVE-2026-25019: Atarim <= 4.3.1 - Missing Authorization

The Visual Feedback, Review & AI Collaboration Tool For WordPress – Atarim plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.3.1. This makes it possible for unauthenticated attackers t...

Published
Jan 30, 2026
Patched Release
4.3.2
Affected Versions
Versions up to 4.3.1
Next Step
Update to 4.3.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-62895
CVE-2025-62895: Atarim <= 4.2.1 - Unauthenticated Information Exposure

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to extract sensitive user or configurati...

Published
Sep 15, 2025
Patched Release
4.2.2
Affected Versions
Versions up to 4.2.1
Next Step
Update to 4.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-60188
CVE-2025-60188: Atarim <= 4.2.1 - Unauthenticated Information Exposure

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to extract sensitive user or configurati...

Published
Jul 29, 2025
Patched Release
4.2.2
Affected Versions
Versions up to 4.2.1
Next Step
Update to 4.2.2 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-60187
CVE-2025-60187: Atarim <= 4.2.1 - Unauthenticated Arbitrary File Upload

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to upload ar...

Published
Jul 29, 2025
Patched Release
4.2.2
Affected Versions
Versions up to 4.2.1
Next Step
Update to 4.2.2 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-60195
CVE-2025-60195: Atarim <= 4.2.1 - Unauthenticated Privilege Escalation

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administ...

Published
Jul 27, 2025
Patched Release
4.2.2
Affected Versions
Versions up to 4.2.1
Next Step
Update to 4.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-26993
CVE-2025-26993: Atarim <= 4.1.0 - Reflected Cross-Site Scripting

The Atarim plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that e...

Published
Feb 23, 2025
Patched Release
4.1.1
Affected Versions
Versions up to 4.1.0
Next Step
Update to 4.1.1 or newer if supported.
Plugin High Patched: Yes CVE-2025-24570
CVE-2025-24570: Atarim <= 4.0.8 - Unauthenticated Stored Cross-Site Scripting

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenti...

Published
Jan 24, 2025
Patched Release
4.0.9
Affected Versions
Versions up to 4.0.8
Next Step
Update to 4.0.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-12104
CVE-2024-12104: Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpf_delete_file and wpf_delete_file functions in all versions up to, and including, 4.0.9. This makes...

Published
Jan 20, 2025
Patched Release
4.1.0
Affected Versions
Versions up to 4.0.9
Next Step
Update to 4.1.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-43290
CVE-2024-43290: Atarim <= 4.0.1 - Missing Authorization via remove_feedbacktool_notice()

The Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_feedbacktool_notice() function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to dismiss feedback tool...

Published
Aug 16, 2024
Patched Release
4.0.2
Affected Versions
Versions up to 4.0.1
Next Step
Update to 4.0.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-7621
CVE-2024-7621: Visual Website Collaboration, Feedback & Project Management – Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the process_wpfeedback_misc_options() function in all versions up to, and including, 4.0.2. This m...

Published
Aug 09, 2024
Patched Release
4.0.3
Affected Versions
Versions up to 4.0.2
Next Step
Update to 4.0.3 or newer if supported.