CVE-2025-62895

7.5

Vito Peleg Atarim · Atarim Visual Collaboration

The Atarim Visual Collaboration WordPress plugin is vulnerable to the insertion of sensitive information into sent data, potentially allowing unauthorized retrieval of embedded sensitive information.

Executive summary

A critical information exposure vulnerability in the Atarim Visual Collaboration plugin allows unauthenticated attackers to retrieve sensitive data from the application.

Vulnerability

This vulnerability is classified as an insertion of sensitive information into sent data (CWE-201), which occurs due to improper data handling within the plugin. An unauthenticated attacker can trigger this flaw over the network with low attack complexity to access sensitive information sent by the application.

Business impact

The exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive organizational or user data. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to data confidentiality, potentially resulting in regulatory non-compliance, loss of user trust, and reputational damage.

Remediation

Immediate Action: Since a specific patch version is not currently identified, users should disable or deactivate the Atarim Visual Collaboration plugin until a secure update is released by the vendor.

Proactive Monitoring: Security teams should review web server access logs for unusual patterns or unexpected data retrieval requests targeting the plugin endpoints.

Compensating Controls: Deploying a Web Application Firewall (WAF) with rules configured to block suspicious outbound data requests or unauthorized access to plugin-specific directories may help mitigate the risk.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing the Atarim Visual Collaboration plugin must treat this vulnerability with high urgency. Because the flaw allows for unauthenticated data exposure, it is recommended to deactivate the plugin immediately until the vendor provides a patched version. Monitor the vendor advisory page for updates and perform a thorough audit of any data that may have been exposed through this plugin prior to deactivation.

Sources

Originally found and disclosed by D01EXPLOIT | Patchstack Bug Bounty Program, per the CVE Program record.