Information is currently not available beyond the provided high-level advisory text. The available content indicates an "Insertion of Sensitive Information Into Sent Data" issue in Vito Peleg Atarim (atarim-visual-collaboration) affecting versions through <= 4.2, where sensitive data is embedded in data sent by the application and can be retrieved by an attacker. No specific vulnerable function/endpoint, data fields, or exploit path details are provided in the source content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a working proof-of-concept exploit for CVE-2025-60188, a critical authentication bypass in the Atarim WordPress plugin. The exploit is implemented as a single Python script (CVE-2025-60188.py) and is accompanied by a README.md with technical details and usage instructions. The exploit works by first leaking the internal site_id from the public REST API endpoint (/wp-json/atarim/v1/db/vc), then using this predictable value as the HMAC key to forge valid signatures for privileged AJAX actions via /wp-admin/admin-ajax.php. Successful exploitation allows an unauthenticated attacker to exfiltrate sensitive system configuration (including license keys) and dump all user PII (usernames, emails, roles, etc.) from the target WordPress site. The code is a functional PoC, requiring only the target URL as input, and demonstrates the full attack chain from information leak to privilege escalation and data exfiltration.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.