Church Admin <= 5.1.1 - Unauthenticated SQL Injection
high
The Church Admin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries int...
- CVSS:
- 7.5
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.2
- Disclosed:
- Aug 10, 2026
CVE-2026-66478 on NVD →
Church Admin <= 5.0.30 - Missing Authorization
medium
The Church Admin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.30. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.0.30
- Fixed in:
- 5.1.0
- Disclosed:
- Aug 3, 2026
CVE-2026-61983 on NVD →
Church Admin <= 5.0.28 - Authenticated (Administrator+) Blind Server-Side Request Forgery via 'audio_url' Parameter
low
The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.28 due to insufficient validation of user-supplied URLs in the 'audio_url' parameter. This makes it possible for authenticated attackers, with Administrator-level access, to make web requests to...
- CVSS:
- 2.2
- Affected:
- up to 5.0.28
- Fixed in:
- 5.0.29
- Disclosed:
- Jan 16, 2026
CVE-2026-0682 on NVD →
Church Admin <= 5.0.26 - Missing Authorization
medium
The Church Admin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.0.26. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.0.26
- Fixed in:
- 5.0.27
- Disclosed:
- Aug 22, 2025
CVE-2025-57896 on NVD →
Church Admin [church-admin] < 5.0.27 (closed)
unknown
[en] Missing Authorization vulnerability in andy_moyle Church Admin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Church Admin: from n/a through 5.0.26.
- Affected:
- up to 5.0.27
- Fixed in:
- 5.0.27
- Disclosed:
- Aug 22, 2025
CVE-2025-57896 on NVD →
Church Admin <= 5.0.23 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...
- CVSS:
- 6.4
- Affected:
- up to 5.0.23
- Fixed in:
- 5.0.24
- Disclosed:
- Apr 16, 2025
CVE-2025-39555 on NVD →
Church Admin <= 5.0.9 - Unauthenticated Information Disclosure
medium
The Church Admin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.0.9. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.10
- Disclosed:
- Apr 16, 2025
CVE-2025-39553 on NVD →
Church Admin [church-admin] < 5.0.24 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin allows Stored XSS. This issue affects Church Admin: from n/a through 5.0.23.
- Affected:
- up to 5.0.24
- Fixed in:
- 5.0.24
- Disclosed:
- Apr 16, 2025
CVE-2025-39555 on NVD →
Church Admin [church-admin] < 5.0.19 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin allows SQL Injection.This issue affects Church Admin: from n/a through 5.0.18.
- Affected:
- up to 5.0.19
- Fixed in:
- 5.0.19
- Disclosed:
- Mar 26, 2025
CVE-2025-26941 on NVD →
Church Admin <= 5.0.18 - Unauthenticated SQL Injection
high
The Church Admin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 5.0.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queri...
- CVSS:
- 7.5
- Affected:
- up to 5.0.18
- Fixed in:
- 5.0.19
- Disclosed:
- Mar 13, 2025
CVE-2025-26941 on NVD →
Church Admin [church-admin] < 5.0.9 (closed)
unknown
[en] Missing Authorization vulnerability in Andy Moyle Church Admin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Church Admin: from n/a through 5.0.8.
- Affected:
- up to 5.0.9
- Fixed in:
- 5.0.9
- Disclosed:
- Dec 6, 2024
CVE-2024-53795 on NVD →
Church Admin <= 5.0.8 - Missing Authorization
medium
The Church Admin plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on an AJAX action in versions up to, and including, 5.0.8. This makes it possible for unauthenticated attackers to send emails.
- CVSS:
- 5.3
- Affected:
- up to 5.0.8
- Fixed in:
- 5.0.9
- Disclosed:
- Dec 2, 2024
CVE-2024-53795 on NVD →
Church Admin [church-admin] < 4.4.5 (closed)
unknown
[en] Missing Authorization vulnerability in Andy Moyle Church Admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through 4.4.4.
- Affected:
- up to 4.4.5
- Fixed in:
- 4.4.5
- Disclosed:
- Nov 1, 2024
CVE-2024-37440 on NVD →
Church Admin [church-admin] < 5.0.0 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Reflected XSS.This issue affects Church Admin: from n/a before 5.0.0.
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.0
- Disclosed:
- Oct 28, 2024
CVE-2024-50438 on NVD →
Church Admin < 5.0.0 - Reflected Cross-Site Scripting
medium
The Church Admin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 5.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into...
- CVSS:
- 6.1
- Affected:
- up to 5.0.0
- Fixed in:
- 5.0.0
- Disclosed:
- Oct 24, 2024
CVE-2024-50438 on NVD →
Church Admin [church-admin] < 4.4.7 (closed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Andy Moyle Church Admin allows Upload a Web Shell to a Web Server.This issue affects Church Admin: from n/a through 4.4.6.
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.7
- Disclosed:
- Jul 9, 2024
CVE-2024-37418 on NVD →
Church Admin <= 4.4.6 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Church Admin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.4.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may mak...
- CVSS:
- 8.8
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Jul 4, 2024
CVE-2024-37418 on NVD →
Church Admin <= 4.4.4 - Missing Authorization
medium
The Church Admin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete-household cas in versions up to, and including, 4.4.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete households.
- CVSS:
- 5.3
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.5
- Disclosed:
- Jun 28, 2024
CVE-2024-37440 on NVD →
Church Admin [church-admin] < 4.4.5 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Stored XSS.This issue affects Church Admin: from n/a through 4.4.4.
- Affected:
- up to 4.4.5
- Fixed in:
- 4.4.5
- Disclosed:
- Jun 21, 2024
CVE-2024-35764 on NVD →
Church Admin <= 4.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject ar...
- CVSS:
- 6.4
- Affected:
- up to 4.4.4
- Fixed in:
- 4.4.5
- Disclosed:
- Jun 17, 2024
CVE-2024-35764 on NVD →
Church Admin [church-admin] < 4.4.0 (closed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Church Admin.This issue affects Church Admin: from n/a through 4.3.6.
- Affected:
- up to 4.4.0
- Fixed in:
- 4.4.0
- Disclosed:
- Jun 3, 2024
CVE-2024-35637 on NVD →
Church Admin <= 4.3.6 - Authenticated (Admin+) Server-Side Request Forgery
medium
The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.3.6. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application which can be use...
- CVSS:
- 5.5
- Affected:
- up to 4.3.6
- Fixed in:
- 4.4.0
- Disclosed:
- May 30, 2024
CVE-2024-35637 on NVD →
Church Admin [church-admin] < 4.1.7 (closed)
unknown
[en] Missing Authorization vulnerability in Andy Moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through 4.1.6.
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.7
- Disclosed:
- May 17, 2024
CVE-2024-31281 on NVD →
Church Admin [church-admin] < 4.2.0 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.32.
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.0
- Disclosed:
- May 10, 2024
CVE-2024-34828 on NVD →
Church Admin <= 4.1.32 - Cross-Site Request Forgery
medium
The Church Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.1.32. This is due to missing or incorrect nonce validation on several functions in the includes/functions.php file. This makes it possible for unauthenticated attackers to perform several unauthoriz...
- CVSS:
- 4.3
- Affected:
- up to 4.1.32
- Fixed in:
- 4.2.0
- Disclosed:
- May 9, 2024
CVE-2024-34828 on NVD →
Church Admin [church-admin] < 4.0.28 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.0.27.
- Affected:
- up to 4.0.28
- Fixed in:
- 4.0.28
- Disclosed:
- Apr 15, 2024
CVE-2024-32090 on NVD →
Church Admin <= 4.0.27 - Cross-Site Request Forgery
medium
The Church Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.27. This is due to missing or incorrect nonce validation on the ca_debug_mode() function. This makes it possible for unauthenticated attackers to enable debug mode via a forged request granted they ca...
- CVSS:
- 4.3
- Affected:
- up to 4.0.27
- Fixed in:
- 4.0.28
- Disclosed:
- Apr 11, 2024
CVE-2024-32090 on NVD →
Church Admin [church-admin] < 4.1.6 (closed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.5.
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.6
- Disclosed:
- Apr 7, 2024
CVE-2024-31280 on NVD →
Church Admin <= 4.1.5 - Authenticated (Subscriber+) Arbitrary File Upload
high
The Church Admin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.1.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may mak...
- CVSS:
- 8.8
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.6
- Disclosed:
- Apr 5, 2024
CVE-2024-31280 on NVD →
Church Admin <= 4.1.6 - Missing Authorization
medium
The Church Admin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the several functions in versions up to, and including, 4.1.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 4.1.6
- Fixed in:
- 4.1.7
- Disclosed:
- Apr 5, 2024
CVE-2024-31281 on NVD →
Church Admin [church-admin] < 4.1.8 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.7.
- Affected:
- up to 4.1.8
- Fixed in:
- 4.1.8
- Disclosed:
- Mar 29, 2024
CVE-2024-30493 on NVD →
Church Admin [church-admin] < 4.1.19 (closed)
unknown
[en] Missing Authorization vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.18.
- Affected:
- up to 4.1.19
- Fixed in:
- 4.1.19
- Disclosed:
- Mar 29, 2024
CVE-2024-30505 on NVD →
Church Admin <= 4.1.7 - Cross-Site Request Forgery
medium
The Church Admin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.7. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site adminis...
- CVSS:
- 4.3
- Affected:
- up to 4.1.7
- Fixed in:
- 4.1.8
- Disclosed:
- Mar 28, 2024
CVE-2024-30493 on NVD →
Church Admin <= 4.1.18 - Missing Authorization
medium
The Church Admin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 4.1.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.
- CVSS:
- 4.3
- Affected:
- up to 4.1.18
- Fixed in:
- 4.1.19
- Disclosed:
- Mar 28, 2024
CVE-2024-30505 on NVD →
Church Admin [church-admin] < 4.0.28 (closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.0.27.
- Affected:
- up to 4.0.28
- Fixed in:
- 4.0.28
- Disclosed:
- Mar 28, 2024
CVE-2024-30244 on NVD →
Church Admin [church-admin] < 4.0.27 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Stored XSS.This issue affects Church Admin: from n/a through 4.0.26.
- Affected:
- up to 4.0.27
- Fixed in:
- 4.0.27
- Disclosed:
- Mar 27, 2024
CVE-2024-30197 on NVD →
Church Admin [church-admin] < 4.1.18 (closed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Stored XSS.This issue affects Church Admin: from n/a through 4.1.17.
- Affected:
- up to 4.1.18
- Fixed in:
- 4.1.18
- Disclosed:
- Mar 27, 2024
CVE-2024-30193 on NVD →
Church Admin <= 4.0.27 - Authenticated (Contributor+) SQL Injection
high
The Church Admin plugin for WordPress is vulnerable to SQL Injection via the 'weeks' value in all versions up to, and including, 4.0.27 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with cont...
- CVSS:
- 8.8
- Affected:
- up to 4.0.27
- Fixed in:
- 4.0.28
- Disclosed:
- Mar 26, 2024
CVE-2024-30244 on NVD →
Church Admin <= 4.1.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via meta-text
medium
The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘meta-text’ parameter in versions up to, and including, 4.1.17 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arb...
- CVSS:
- 6.4
- Affected:
- up to 4.1.17
- Fixed in:
- 4.1.18
- Disclosed:
- Mar 25, 2024
CVE-2024-30193 on NVD →
Church Admin <= 4.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
medium
The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.0.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level...
- CVSS:
- 6.4
- Affected:
- up to 4.0.26
- Fixed in:
- 4.0.27
- Disclosed:
- Mar 25, 2024
CVE-2024-30197 on NVD →
Church Admin [church-admin] < 3.8.0 (closed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 3.7.56.
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Nov 13, 2023
CVE-2023-38515 on NVD →
Church Admin [church-admin] < 3.7.6 (closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions.
- Affected:
- up to 3.7.6
- Fixed in:
- 3.7.6
- Disclosed:
- Aug 16, 2023
CVE-2023-30782 on NVD →
Church Admin <= 3.7.56 - Server-Side Request Forgery via church_admin_import_csv
medium
The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.7.56 via the church_admin_import_csv function when importing from a csv file. This can allow authenticated attackers with administrator access to make web requests to arbitrary locations originating fr...
- CVSS:
- 5.5
- Affected:
- up to 3.7.56
- Fixed in:
- 3.8.0
- Disclosed:
- Jul 26, 2023
CVE-2023-38515 on NVD →
Church Admin [church-admin] < 3.7.30 (closed)
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.29 versions.
- Affected:
- up to 3.7.30
- Fixed in:
- 3.7.30
- Disclosed:
- Jun 23, 2023
CVE-2023-34021 on NVD →
Church Admin <= 3.7.29 - Reflected Cross-Site Scripting
medium
The Church Admin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.7.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 3.7.29
- Fixed in:
- 3.7.30
- Disclosed:
- Jun 13, 2023
CVE-2023-34021 on NVD →
Church Admin <= 3.7.5 - Reflected Cross-Site Scripting
medium
The Church Admin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $what variable parameter in versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that ex...
- CVSS:
- 6.1
- Affected:
- up to 3.7.5
- Fixed in:
- 3.7.6
- Disclosed:
- Apr 18, 2023
CVE-2023-30782 on NVD →
Church Admin [church-admin] < 3.4.135 (closed)
unknown
[en] The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plug...
- Affected:
- up to 3.4.135
- Fixed in:
- 3.4.135
- Disclosed:
- Mar 28, 2022
CVE-2022-0833 on NVD →
Church Admin <= 3.4.134 - Cross-Site Request Forgery leading to Plugin Backup Disclosure
medium
The Church Admin plugin for WordPress is vulnerable to Unauthenticated Backup Disclosure in versions up to, and including, 3.4.134. Attackers can repeatedly request the "refresh-backup" action and simultaneously request a publicly accessible temporary file generated by the plugin in order to disclose the final backup f...
- CVSS:
- 4.3
- Affected:
- up to 3.4.135
- Fixed in:
- 3.4.135
- Disclosed:
- Mar 7, 2022
CVE-2022-0833 on NVD →
Church Admin [church-admin] < 1.2550 (closed)
unknown
[en] The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
- Affected:
- up to 1.2550
- Fixed in:
- 1.2550
- Disclosed:
- Aug 16, 2019
CVE-2018-20971 on NVD →
Church Admin < 1.2550 - Cross-Site Request Forgery
high
The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan.
- CVSS:
- 8.8
- Affected:
- up to 1.2550
- Fixed in:
- 1.2550
- Disclosed:
- Feb 14, 2018
CVE-2018-20971 on NVD →
Church Admin [church-admin] < 0.565 (closed)
unknown
Unauthenticated Directory Traversal vulnerability found in WordPress Church Admin plugin (versions <=0.564).
- Affected:
- up to 0.565
- Fixed in:
- 0.565
- Disclosed:
- Jan 10, 2018
Church Admin [church-admin] < 0.810 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.
- Affected:
- up to 0.810
- Fixed in:
- 0.810
- Disclosed:
- May 28, 2015
CVE-2015-4127 on NVD →
Church Admin < 0.810 - Stored Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.
- CVSS:
- 6.1
- Affected:
- up to 0.810
- Fixed in:
- 0.810
- Disclosed:
- May 22, 2015
CVE-2015-4127 on NVD →
Church Admin [church-admin] < 0.33.4.6 (closed)
unknown
This plugin is prone to a cross site scripting vulnerability in includes/validate.php id parameter.
Update the plugin.
- Affected:
- up to 0.33.4.6
- Fixed in:
- 0.33.4.6
- Disclosed:
- Aug 1, 2014
Church Admin [church-admin] < 0.33.4.6 (closed)
unknown
WordPress Church_Admin plugin's "id" parameter is prone to a cross-site scripting vulnerability. It fails to properly clean up user-supplied input. An attacker may execute arbitrary script code in the browser of an user in the context of the affected site. In this way the attacker can steal cookie-based authenticatio...
- Affected:
- up to 0.33.4.6
- Fixed in:
- 0.33.4.6
- Disclosed:
- Jul 6, 2012
Church Admin [church-admin] < 0.565 (closed)
unknown
The "key" parameter of download.php from plugins/church-admin/display/download.php is not sanitized and is vulnerable to a directory traversal type of attack.
- Affected:
- up to 0.565
- Fixed in:
- 0.565
Church Admin [church-admin] < 5.0.10 (closed)
unknown
- Affected:
- up to 5.0.10
- Fixed in:
- 5.0.10
CVE-2025-39553 on NVD →
Church Admin [church-admin] < 0.4.3 (closed)
unknown
The Church Admin WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 0.4.3
- Fixed in:
- 0.4.3