The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metadata for all users.
History

Tue, 12 Aug 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared 10up
10up simple Local Avatars
Wordpress
Wordpress wordpress
Vendors & Products 10up
10up simple Local Avatars
Wordpress
Wordpress wordpress

Tue, 12 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Aug 2025 06:45:00 +0000

Type Values Removed Values Added
Description The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metadata for all users.
Title Simple Local Avatars <= 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Avatar Migration
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-08-12T06:42:41.969Z

Updated: 2025-08-12T16:04:34.828Z

Reserved: 2025-08-01T17:50:18.360Z

Link: CVE-2025-8482

cve-icon Vulnrichment

Updated: 2025-08-12T16:04:28.250Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-12T07:15:30.543

Modified: 2025-08-12T14:25:33.177

Link: CVE-2025-8482

cve-icon Redhat

No data.