VYPR
Medium severity4.3NVD Advisory· Published Mar 13, 2026· Updated Apr 22, 2026

CVE-2026-32447

CVE-2026-32447

Description

Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Atarim: from n/a through <= 4.3.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Atarim WordPress plugin <=4.3.2 allows unprivileged attackers to exploit broken access control, fixed in version 4.3.3.

Vulnerability

The Atarim plugin for WordPress (atarim-visual-collaboration) contains a missing authorization vulnerability in versions up to and including 4.3.2. This is a broken access control issue where the plugin fails to properly enforce access control checks on certain functions, allowing unprivileged users to perform actions that should require higher privileges [1].

Exploitation

An attacker can exploit this vulnerability without needing authentication, simply by sending crafted requests to the WordPress site. The lack of proper authorization checks means that any user, including unauthenticated visitors, can trigger privileged operations within the plugin [1].

Impact

Successful exploitation allows an attacker to execute actions that are normally restricted to higher-privileged users, such as administrators. This could lead to unauthorized modification of settings, data exposure, or other malicious activities depending on the plugin's capabilities [1].

Mitigation

The vulnerability has been addressed in version 4.3.3 of the Atarim plugin. Users are strongly advised to update to this version or later immediately. For those unable to update, contacting the hosting provider or web developer for assistance is recommended [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.