Unrestricted File Upload Vulnerability in Atarim Visual Collaboration by Vito Peleg
CVE-2025-60187

4.8MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
6 November 2025

What is CVE-2025-60187?

The Atarim Visual Collaboration plugin, developed by Vito Peleg, contains a vulnerability that allows attackers to upload files of dangerous types without proper restrictions. This flaw can be exploited to execute malicious files on the server, potentially leading to further compromises. The issue affects versions of Atarim up to and including 4.2, highlighting the need for immediate updates to mitigate the risks associated with arbitrary file uploads.

Affected Version(s)

Atarim <= n/a

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Denver Jackson | Patchstack Bug Bounty Program
.
CVE-2025-60187 : Unrestricted File Upload Vulnerability in Atarim Visual Collaboration by Vito Peleg