plugin

Simple Local Avatars Vulnerabilities

6 known security issues reported for the Simple Local Avatars WordPress plugin. Most recent disclosed Aug 11, 2025.

1 high 4 medium 1 low

Running Simple Local Avatars on your site? Check whether your installed version is affected.

Scan your site free

Simple Local Avatars <= 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Avatar Migration

medium

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metada...

CVSS:
4.3
Affected:
up to 2.8.4
Fixed in:
2.8.5
Disclosed:
Aug 11, 2025

CVE-2025-8482 on NVD →

Simple Local Avatars <= 2.7.11 - Missing Authorization to Authenticated (Subscriber+) User Cache Clearing

medium

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear user c...

CVSS:
4.3
Affected:
up to 2.7.11
Fixed in:
2.8.0
Disclosed:
Nov 15, 2024

CVE-2024-10786 on NVD →

Simple Local Avatars <= 2.7.10 - Cross-Site Request Forgery via save_default_avatar_file_id()

medium

The Simple Local Avatars plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.10. This is due to missing or incorrect nonce validation on the save_default_avatar_file_id() function. This makes it possible for unauthenticated attackers to set the default avatar file via...

CVSS:
4.3
Affected:
up to 2.7.10
Fixed in:
2.7.11
Disclosed:
Aug 7, 2024

CVE-2024-43116 on NVD →

simple-git < 3.16.0 - Remote Code Execution

high

The package simple-git is vulnerable to Remote Code Execution in versions before 3.16.0 via the clone(), pull(), push() and listRemote() methods due to improper input sanitization. This is due to an incomplete fix of CVE-2022-25912. WordPress plugins and themes may be using this package, however, they may not be vulner...

CVSS:
8.1
Affected:
up to 2.7.3
Fixed in:
2.7.4
Disclosed:
Feb 23, 2023

CVE-2022-25860 on NVD →

http-cache-semantics < 4.1.1 - Regular Expression Denial of Service (ReDoS)

medium

The package http-cache-semantics is vulnerable to Regular Expression Denial of Service (ReDoS) in versions before 4.1.1 via the cache-control HTTP header. WordPress plugins and themes may be using this package, however, they may not be vulnerable to exploitation.

CVSS:
5.3
Affected:
up to 2.7.3
Fixed in:
2.7.4
Disclosed:
Feb 23, 2023

CVE-2022-25881 on NVD →

terser (JS Package) < 5.14.2 - Denial of Service

low

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.

CVSS:
3.7
Affected:
up to 2.5.0
Fixed in:
2.6.0
Disclosed:
Jul 14, 2022

CVE-2022-25858 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database