Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hhg-39mv-cqcm

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metadata for all users.

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metadata for all users.

EPSS

Процентиль: 7%
0.0003
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
29 дней назад

The Simple Local Avatars plugin for WordPress is vulnerable to unauthorized modification of data in version 2.8.4. This is due to a missing capability check on the migrate_from_wp_user_avatar() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to migrate avatar metadata for all users.

EPSS

Процентиль: 7%
0.0003
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862