📦 Church Admin

by Church Admin Project

🔍 What is Church Admin?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-37418

CRITICAL CVSS 9.9 Jul 9, 2024

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Church Admin plugin. Attackers can achieve remote code execution and full server c...

CVE-2024-31280

CRITICAL CVSS 9.9 Apr 7, 2024

CVE-2024-31280 is an arbitrary file upload vulnerability in the WordPress Church Admin plugin that allows attackers to upload malicious files to vulnerable websites. This affects all versions up to 4....

CVE-2023-34021

HIGH CVSS 7.1 Jun 23, 2023

Unauthenticated reflected cross-site scripting (XSS) vulnerability in the Church Admin WordPress plugin allows attackers to inject malicious scripts via crafted URLs. When users click malicious links,...

CVE-2024-37440

MEDIUM CVSS 4.3 Nov 1, 2024

This CVE describes a missing authorization vulnerability in the Church Admin WordPress plugin that allows attackers to bypass access controls and perform unauthorized actions. It affects all versions ...

CVE-2024-35637

MEDIUM CVSS 4.4 Jun 3, 2024

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the Church Admin WordPress plugin. It allows attackers to make the vulnerable server send unauthorized requests to internal or ...

CVE-2024-31281

MEDIUM CVSS 6.3 May 17, 2024

This CVE describes a Missing Authorization vulnerability in the Church Admin WordPress plugin that allows attackers to exploit incorrectly configured access control security levels. It affects all ver...

CVE-2024-34828

MEDIUM CVSS 4.3 May 14, 2024

This Cross-Site Request Forgery (CSRF) vulnerability in the Church Admin WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions. It affects all Word...