PT-2025-32632 · WordPress · Simple Local Avatars

Håkon Harnes

·

Published

2025-08-12

·

Updated

2025-08-12

·

CVE-2025-8482

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Simple Local Avatars plugin for WordPress version 2.8.4
Description: The Simple Local Avatars plugin for WordPress is susceptible to unauthorized data modification due to an incomplete capability check within the migrate from wp user avatar() function. Authenticated attackers with subscriber-level access or higher can exploit this to migrate avatar metadata for all users.
Recommendations: Update to a newer version of the Simple Local Avatars plugin that addresses this issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-8482

Affected Products

Simple Local Avatars