logo

PoC Released for Atarim Plugin Auth Bypass Vulnerability

ID: 6ca9b529-6806-5b39-9ea1-b7be6d565a88

STIX ID: report--6ca9b529-6806-5b39-9ea1-b7be6d565a88

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Divya

...
...

The report details a critical authentication bypass (CVE-2025-60188) in the Atarim WordPress plugin where a publicly exposed site_id is used as the HMAC secret, enabling unauthenticated attackers to forge signatures and access administrative AJAX endpoints that expose PII and system settings; a public Python PoC is available and site owners are urged to update and harden signing practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.