CVE · High

CVE-2022-25881 — Simple Local Avatars [simple-local-avatars] < 2.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-25881 Simple Local Avatars [simple-local-avatars] < 2.7.4 Inefficient Regular Expression Complexity High 7.5 < 2.7.4 2.7.4 2023-01-31

CVE-2022-25881

Simple Local Avatars versions prior to 2.7.4 contain a Regular Expression Denial of Service vulnerability through the http-cache-semantics package affecting how cache-control HTTP headers are processed. This vulnerability could potentially allow attackers to cause a denial of service condition by crafting malicious cache-control headers. The flaw was resolved in version 2.7.4 and later. While the underlying package contains this ReDoS issue, actual exploitability depends on the specific implementation within the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.