Church Admin

Information

Software Type Plugin
Software Slug church-admin (view on wordpress.org)
Software Status Active
Software Author andy_moyle
Software Website www.churchadminplugin.com
Software Downloads 438,416
Software Active Installs 1,000
Software Record Last Updated October 29, 2024

19 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Church Admin <= 4.4.6 - Authenticated (Subscriber+) Arbitrary File Upload Patched CVE-2024-37418 8.8 Peng Zhou July 4, 2024
Church Admin <= 4.4.4 - Missing Authorization Patched CVE-2024-37440 5.3 Ngô Thiên An (ancorn_) June 28, 2024
Church Admin <= 4.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Patched CVE-2024-35764 6.4 Ngô Thiên An (ancorn_) June 17, 2024
Church Admin <= 4.3.6 - Authenticated (Admin+) Server-Side Request Forgery Patched CVE-2024-35637 5.5 Yuchen Ji May 30, 2024
Church Admin <= 4.1.32 - Cross-Site Request Forgery Patched CVE-2024-34828 4.3 Dhabaleshwar Das May 9, 2024
Church Admin <= 4.0.27 - Cross-Site Request Forgery Patched CVE-2024-32090 4.3 Dhabaleshwar Das April 11, 2024
Church Admin <= 4.1.5 - Authenticated (Subscriber+) Arbitrary File Upload Patched CVE-2024-31280 8.8 Peng Zhou April 5, 2024
Church Admin <= 4.1.6 - Missing Authorization Patched CVE-2024-31281 4.3 Peng Zhou April 5, 2024
Church Admin <= 4.1.7 - Cross-Site Request Forgery Patched CVE-2024-30493 4.3 Peng Zhou March 28, 2024
Church Admin <= 4.1.18 - Missing Authorization Patched CVE-2024-30505 4.3 CatFather March 28, 2024
Church Admin <= 4.0.27 - Authenticated (Contributor+) SQL Injection Patched CVE-2024-30244 8.8 LVT-tholv2k March 26, 2024
Church Admin <= 4.1.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via meta-text Patched CVE-2024-30193 6.4 CatFather March 25, 2024
Church Admin <= 4.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode Patched CVE-2024-30197 6.4 LVT-tholv2k March 25, 2024
Church Admin <= 3.7.56 - Server-Side Request Forgery via church_admin_import_csv Patched CVE-2023-38515 5.5 Yuchen Ji July 26, 2023
Church Admin <= 3.7.29 - Reflected Cross-Site Scripting Patched CVE-2023-34021 6.1 Phd June 13, 2023
Church Admin <= 3.7.5 - Reflected Cross-Site Scripting Patched CVE-2023-30782 6.1 Le Ngoc Anh April 18, 2023
Church Admin <= 3.4.134 - Cross-Site Request Forgery leading to Plugin Backup Disclosure Patched CVE-2022-0833 4.3 cydave March 7, 2022
Church Admin < 1.2550 - Cross-Site Request Forgery Patched CVE-2018-20971 8.8 February 14, 2018
Church Admin < 0.810 - Stored Cross-Site Scripting Patched CVE-2015-4127 6.1 Viktor Gazdag May 22, 2015

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation