MEDIUM
Simple Local Avatars <= 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Avatar Migration
Published Aug 12, 2025
4.3
MEDIUMCVSS 3.1
EPSS 0.26%
Description
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metadata for all users.
Affected products
-
- Version 0StatusaffectedConstraints<=2.8.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| 10up | Simple Local Avatars | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-24225 Advisory
- https://plugins.trac.wordpress.org/browser/simple-local-avatars/tags/2.8.4/includes/class-simple-local-avatars.php#L123
- https://plugins.trac.wordpress.org/browser/simple-local-avatars/tags/2.8.4/includes/class-simple-local-avatars.php?marks=1663-1672#L1663
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3340223%40simple-local-avatars&new=3340223%40simple-local-avatars&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/69d78334-2b38-43ee-acf6-c073d5826213?source=cve
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Aug 12, 2025
Updated Apr 8, 2026
Reserved Aug 1, 2025
Link CVE-2025-8482
CISA Vulnrichment
Updated Aug 12, 2025
ENISA EUVD
EUVD-2025-24225 Assigner Wordfence
Published Aug 12, 2025
Updated Apr 8, 2026
Exploited since n/a
Link EUVD-2025-24225