File Deletion Vulnerability in Atarim Plugin for WordPress
CVE-2026-19942
8.1HIGH
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-19942?
The Atarim - AI Agency for WordPress plugin is susceptible to arbitrary file deletion due to inadequate validation of file paths in its functions. This vulnerability affects all versions up to and including 5.1.1. Authenticated users with author-level access and higher can manipulate the system to delete arbitrary files, potentially leading to further security breaches such as remote code execution. Attackers can exploit this vulnerability by altering the metadata of attachments, making it possible to execute unauthorized deletions and compromise the integrity of the server.
Affected Version(s)
Atarim β AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback 0 <= 5.1.1