PT-2024-30303 · WordPress · Simple Local Avatars

·

CVE-2024-43116

·

Published

2024-08-26

·

Updated

2024-09-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simple Local Avatars versions 2.7.10 and earlier
Description A Cross-Site Request Forgery (CSRF) issue affects the Simple Local Avatars plugin. This allows an attacker to perform unintended actions on a user's account. The estimated number of potentially affected devices is not provided.
Recommendations For versions 2.7.10 and earlier, upgrade to version 2.7.11 to remediate the issue. As a temporary workaround, consider restricting access to sensitive areas of the site to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43116

Affected Products

Simple Local Avatars