← back to popular plugins
wordfence / plugin · simple-local-avatars

Simple Local Avatars

simple-local-avatars
total installs
100,000
total vulns
1
critical
0
high
0
medium
1
low
0
latest vuln
patched
1
unpatched
0
avg time to patch
vulnerabilities (1)
Simple Local Avatars <= 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Avatar Migration
medium ✓ patched
cvss score 4.3
cwe CWE-862: Missing Authorization
published Aug 11, 2025
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metadata for all users.