Extension WordPress

Vulnérabilités Simple Local Avatars

Cette page rassemble les failles publiées pour Simple Local Avatars, leurs plages de versions affectées et les correctifs signalés dans la base locale.

6Vulnérabilités
0Critiques
6Avec correctif
8,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Simple Local Avatars

6 fiches

CVE-2025-8482 Moyenne · 4,3
Simple Local Avatars

Simple Local Avatars <= 2.8.4 – Missing Authorization to Authenticated (Subscriber+) Avatar Migration

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level…

Versions affectées

*-2.8.4

Correctif

2.8.5

Publication

11/08/2025

CVE-2024-10786 Moyenne · 4,3
Simple Local Avatars

Simple Local Avatars <= 2.7.11 – Missing Authorization to Authenticated (Subscriber+) User Cache Clearing

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the sla_clear_user_cache function in all versions up to, and including, 2.7.11. This makes it possible for authenticated attackers,…

Versions affectées

*-2.7.11

Correctif

2.8.0

Publication

15/11/2024

CVE-2024-43116 Moyenne · 4,3
Simple Local Avatars

Simple Local Avatars <= 2.7.10 – Cross-Site Request Forgery via save_default_avatar_file_id()

The Simple Local Avatars plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.10. This is due to missing or incorrect nonce validation on the save_default_avatar_file_id() function. This makes it possible for…

Versions affectées

*-2.7.10

Correctif

2.7.11

Publication

07/08/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités