Plugin inspection:

Simple Local Avatars

Use with caution

Last revised:

Confidence: Medium
This plugin has been given a short, targeted code review.

Before using this plugin, you should carefully consider these findings. Read more about this recommendation.

Warnings

This recommendation applies to version 2.0 of this plugin, but the most recent version is 2.8.5. These findings may no longer be correct.

Findings

  • Appears to delete files which are stored in usermeta. This may allow an attacker to delete arbitrary files if they can add usermeta fields (eg. through a vulnerability in some other plugin)

Reason for the 'Use with caution' result

The plugin contains or is likely to contain a vulnerability which could be exploited by a privileged user to affect the site’s confidentiality, integrity or availability in a manner exceeding their privileges:

  • May allow an attacker able to add arbitrary data to a usermeta field the ability to delete arbitrary files