WordPress security by component
Church Admin
Plugin description
Church Admin is a WordPress component with 27 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 9.9.
Plugin slug:
church-adminLatest vulnerability
CVE-2026-61983: Church Admin: A security weakness
Church Admin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.0.30.
| Safe version |
|
||
|---|---|---|---|
| Jul 13, 2026 |
CVE-2026-61983
Church Admin: A security weakness
Church Admin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.0.30.
|
5.1.0 |
CVE5.3
NVDPending
|
| Jan 17, 2026 |
CVE-2026-0682
Church Admin: Server-side request forgery
Church Admin is affected by server-side request forgery. Exploitation requires at least administrator-level access. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE2.2
NVDPending
|
| Sep 09, 2025 |
CVE-2025-39553
Church Admin: A security weakness
Church Admin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Aug 22, 2025 |
CVE-2025-57896
Church Admin: A security weakness
Church Admin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 16, 2025 |
CVE-2025-39555
Church Admin: Cross-site scripting
Church Admin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Mar 26, 2025 |
CVE-2025-26941
Church Admin: SQL injection
Church Admin is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVDPending
|
| Dec 06, 2024 |
CVE-2024-53795
Church Admin: A security weakness
Church Admin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 01, 2024 |
CVE-2024-37440
Church Admin: A security weakness
Church Admin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Oct 28, 2024 |
CVE-2024-50438
Church Admin: Cross-site scripting
Church Admin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jul 09, 2024 |
CVE-2024-37418
Church Admin: Dangerous file upload
Church Admin is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.9
NVDPending
|
| Jun 21, 2024 |
CVE-2024-35764
Church Admin: Cross-site scripting
Church Admin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 03, 2024 |
CVE-2024-35637
Church Admin: Server-side request forgery
Church Admin is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.4
NVDPending
|
| May 17, 2024 |
CVE-2024-31281
Church Admin: A security weakness
Church Admin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVDPending
|
| May 14, 2024 |
CVE-2024-34828
Church Admin: Cross-site request forgery
Church Admin is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 15, 2024 |
CVE-2024-32090
Church Admin: Cross-site request forgery
Church Admin is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 07, 2024 |
CVE-2024-31280
Church Admin: Dangerous file upload
Church Admin is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.9
NVD8.8
|
| Mar 29, 2024 |
CVE-2024-30505
Church Admin: A security weakness
Church Admin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Mar 29, 2024 |
CVE-2024-30493
Church Admin: Cross-site request forgery
Church Admin is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 28, 2024 |
CVE-2024-30244
Church Admin: SQL injection
Church Admin is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Mar 27, 2024 |
CVE-2024-30197
Church Admin: Cross-site scripting
Church Admin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Mar 27, 2024 |
CVE-2024-30193
Church Admin: Cross-site scripting
Church Admin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Nov 13, 2023 |
CVE-2023-38515
Church Admin: Server-side request forgery
Church Admin is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE5.5
NVD4.9
|
| Aug 16, 2023 |
CVE-2023-30782
Church Admin: Cross-site scripting
Church Admin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jun 23, 2023 |
CVE-2023-34021
Church Admin: Cross-site scripting
Church Admin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Mar 28, 2022 |
CVE-2022-0833
Church Admin: Cross-site request forgery
Church Admin is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Aug 16, 2019 |
CVE-2018-20971
Church Admin: Cross-site request forgery
Church Admin is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| May 28, 2015 |
CVE-2015-4127
Church Admin: Cross-site scripting
Church Admin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|