Back

MEDIUM

Simple Local Avatars <= 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Avatar Migration

Published Aug 12, 2025

Description

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metadata for all users.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Aug 12, 2025
Updated Apr 8, 2026
Reserved Aug 1, 2025
CISA Vulnrichment
Updated Aug 12, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Wordfence
Published Aug 12, 2025
Updated Apr 8, 2026
Exploited since n/a
EUVD-2025-24225