Medium 4.3
2025-08-12< 2.8.5
WordPress Simple Local Avatars Plugin <= 2.8.4 is vulnerable to Broken Access Control
Minimum safe version
2.8.5
Update to 2.8.5 or later to address 5 fixable vulnerabilities
WordPress Simple Local Avatars Plugin <= 2.8.4 is vulnerable to Broken Access Control
CVE-2024-10786
CVE-2024-43116
http-cache-semantics < 4.1.1 - Regular Expression Denial of Service (ReDoS)
simple-git < 3.16.0 - Remote Code Execution