CVE-2024-43116
The Simple Local Avatars plugin contains a cross-site request forgery vulnerability affecting versions through 2.7.10 stemming from inadequate nonce checks in the save_default_avatar_file_id() function. An attacker could exploit this flaw by crafting a malicious request that, if clicked by an administrator, would allow the attacker to modify the site's default avatar setting. The vulnerability requires social engineering to succeed but poses a risk to site configuration integrity.
Based on public CVE data (MITRE/NVD).