CVE-2025-60188

HIGH NUCLEI

Atarim <= 4.2.1 - Sensitive Data Exposure via Embedded Data Retrieval

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2025-60188. PoCs published by Mohammad Hossein Sadeghian, m4sh-wacker, maxturbaman. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit targets an information exposure vulnerability in the Atarim WordPress Plugin (<4.2.2) by abusing improperly signed AJAX requests to extract sensitive site configuration, license keys, and user PII (including admin credentials). The PoC demonstrates unauthenticated access to privileged data via HMAC signature spoofing using a leaked site ID.

Description

Insertion of Sensitive Information Into Sent Data vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Retrieve Embedded Sensitive Data.This issue affects Atarim: from n/a through <= 4.2.1.

Exploits (3)

exploitdb WORKING POC
by Mohammad Hossein Sadeghian · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52628

This exploit targets an information exposure vulnerability in the Atarim WordPress Plugin (<4.2.2) by abusing improperly signed AJAX requests to extract sensitive site configuration, license keys, and user PII (including admin credentials). The PoC demonstrates unauthenticated access to privileged data via HMAC signature spoofing using a leaked site ID.

Classification
Working Poc 98%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Atarim WordPress Plugin versions < 4.2.2
No auth needed
Prerequisites: Target must have Atarim plugin installed (<4.2.2) · WordPress REST API and admin-ajax.php endpoints must be accessible · Site ID must be extractable via unauthenticated REST endpoint
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →
nomisec WORKING POC 22 stars
by m4sh-wacker · poc
https://github.com/m4sh-wacker/CVE-2025-60188-Atarim-Plugin-Exploit

This PoC exploits CVE-2025-60188, an authentication bypass vulnerability in the Atarim WordPress plugin via HMAC forgery. It extracts sensitive system configurations and user PII by leveraging a predictable site_id as the HMAC key.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Atarim WordPress Plugin
No auth needed
Prerequisites: Target must have the vulnerable Atarim plugin installed · Network access to the target WordPress site
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
gitlab WORKING POC
by maxturbaman · poc
https://gitlab.com/maxturbaman/CVE-2025-60188-Atarim-Plugin-Exploit

The repository contains a functional exploit for CVE-2025-60188, which leverages an HMAC forgery vulnerability in the Atarim WordPress plugin to bypass authentication and exfiltrate sensitive user data and system configurations.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Atarim WordPress Plugin
No auth needed
Prerequisites: Target URL with vulnerable Atarim plugin installed
mistral-large-3 · analyzed Jun 28, 2026 Full analysis →

Nuclei Templates (1)

Atarim < 4.2.2 - Sensitive Information Exposure
HIGHVERIFIEDby m4sh_wacker
FOFA: body="atarim"

Scores

CVSS v3 7.5
EPSS 0.0354
EPSS Percentile 88.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (2)
Vito Peleg/Atarim < 4.2.1
Vito Peleg/Atarim < <= 4.2
Published Nov 06, 2025
Tracked Since Feb 18, 2026