Extension WordPress
Vulnérabilités Simple Local Avatars
Cette page rassemble les failles publiées pour Simple Local Avatars, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Simple Local Avatars
6 fiches
Simple Local Avatars <= 2.8.4 – Missing Authorization to Authenticated (Subscriber+) Avatar Migration
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level…
*-2.8.4
2.8.5
11/08/2025
Simple Local Avatars <= 2.7.11 – Missing Authorization to Authenticated (Subscriber+) User Cache Clearing
The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated attackers,…
*-2.7.11
2.8.0
15/11/2024
Simple Local Avatars <= 2.7.10 – Cross-Site Request Forgery via save_default_avatar_file_id()
The Simple Local Avatars plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.10. This is due to missing or incorrect nonce validation on the save_default_avatar_file_id() function. This makes it possible for…
*-2.7.10
2.7.11
07/08/2024
simple-git < 3.16.0 – Remote Code Execution
The package simple-git is vulnerable to Remote Code Execution in versions before 3.16.0 via the clone(), pull(), push() and listRemote() methods due to improper input sanitization. This is due to an incomplete fix of CVE-2022-25912. WordPress plugins and…
*-2.7.3
2.7.4
23/02/2023
http-cache-semantics < 4.1.1 – Regular Expression Denial of Service (ReDoS)
The package http-cache-semantics is vulnerable to Regular Expression Denial of Service (ReDoS) in versions before 4.1.1 via the cache-control HTTP header. WordPress plugins and themes may be using this package, however, they may not be vulnerable to exploitation.
*-2.7.3
2.7.4
23/02/2023
terser (JS Package) < 5.14.2 – Denial of Service
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. Some WordPress plugins and themes use this dependency, however, are not vulnerable…
*-2.5.0
2.6.0
14/07/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.