CVE · Critical

CVE-2022-25860 — Simple Local Avatars [simple-local-avatars] < 2.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-25860 Simple Local Avatars [simple-local-avatars] < 2.7.4 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Critical 9.8 < 2.7.4 2.7.4 2023-01-24

CVE-2022-25860

The Simple Local Avatars plugin before version 2.7.4 contains a remote code execution vulnerability stemming from inadequate input validation in the underlying simple-git package used by the plugin. The flaw exists in multiple methods and represents an incomplete remediation of a previously identified vulnerability. While WordPress plugins and themes incorporating this package could be affected, actual exploitability depends on their specific usage patterns.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.