PoC Released for Atarim Plugin Auth Bypass Vulnerability
ID: 6ca9b529-6806-5b39-9ea1-b7be6d565a88
STIX ID: report--6ca9b529-6806-5b39-9ea1-b7be6d565a88
Feed Name: GBHackers
Threat Score
The report details a critical authentication bypass (CVE-2025-60188) in the Atarim WordPress plugin where a publicly exposed site_id is used as the HMAC secret, enabling unauthenticated attackers to forge signatures and access administrative AJAX endpoints that expose PII and system settings; a public Python PoC is available and site owners are urged to update and harden signing practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
