Church Admin

Information

Software Type Plugin
Software Slug church-admin (view on wordpress.org)
Software Status Active
Software Author andy_moyle
Software Website www.churchadminplugin.com
Software Downloads 411,816
Software Active Installs 1,000
Software Record Last Updated April 20, 2024

14 Vulnerabilities

Title CVE ID CVSS Researchers Date
Church Admin <= 4.0.27 - Cross-Site Request Forgery CVE-2024-32090 4.3 Dhabaleshwar Das April 11, 2024
Church Admin <= 4.1.6 - Missing Authorization CVE-2024-31281 4.3 Peng Zhou April 5, 2024
Church Admin <= 4.1.5 - Authenticated (Subscriber+) Arbitrary File Upload CVE-2024-31280 8.8 Peng Zhou April 5, 2024
Church Admin <= 4.1.18 - Missing Authorization CVE-2024-30505 4.3 CatFather March 28, 2024
Church Admin <= 4.1.7 - Cross-Site Request Forgery CVE-2024-30493 4.3 Peng Zhou March 28, 2024
Church Admin <= 4.0.27 - Authenticated (Contributor+) SQL Injection CVE-2024-30244 8.8 LVT-tholv2k March 26, 2024
Church Admin <= 4.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode CVE-2024-30197 6.4 LVT-tholv2k March 25, 2024
Church Admin <= 4.1.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via meta-text CVE-2024-30193 6.4 CatFather March 25, 2024
Church Admin <= 3.7.56 - Server-Side Request Forgery via church_admin_import_csv CVE-2023-38515 5.5 Yuchen Ji July 26, 2023
Church Admin <= 3.7.29 - Reflected Cross-Site Scripting CVE-2023-34021 6.1 Phd June 13, 2023
Church Admin <= 3.7.5 - Reflected Cross-Site Scripting CVE-2023-30782 6.1 Le Ngoc Anh April 18, 2023
Church Admin <= 3.4.134 - Cross-Site Request Forgery leading to Plugin Backup Disclosure CVE-2022-0833 4.3 cydave March 7, 2022
Church Admin < 1.2550 - Cross-Site Request Forgery CVE-2018-20971 8.8 February 14, 2018
Church Admin < 0.810 - Stored Cross-Site Scripting CVE-2015-4127 6.1 Viktor Gazdag May 22, 2015

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation