What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Add Local Avatar.This issue affects Add Local Avatar: from n/a through 12.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Peter Sterling Add Local Avatar.This issue affects Add Local Avatar: from n/a through 12.1.
Explanation of Vulnerability in Simple Terms
Add Local Avatar versions up to 12.1 contain a cross-site request forgery (CSRF) vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. An attacker can craft a malicious link or page that, when visited by a logged-in site administrator, triggers unwanted changes without the user's knowledge. The vulnerability requires user interaction but can compromise site integrity.
What an attacker can do
Perform unauthorized actions on the site by tricking a logged-in admin into visiting a malicious page.
Potential impact on your site
An attacker can modify site settings or data through a logged-in admin's browser without their consent.
Conditions required to exploit
A site admin must visit an attacker-controlled page while logged into WordPress.
Key dates
External resources
Related vulnerabilities