CVE-2022-0833: Church Admin < 3.4.135 - Unauthenticated Plugin's Backup Disclosure
The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as requested files, allowing unauthenticated attackers to repeatedly request the "refresh-backup" action, and simultaneously keep requesting a publicly accessible temporary file generated by the plugin in order to disclose the final backup filename, which can then be fetched by the attacker to download the backup of the plugin's DB data
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0833?
CVE-2022-0833 is a vulnerability in the Church Admin WordPress plugin before version 3.4.135.
What is the severity of CVE-2022-0833?
CVE-2022-0833 has a severity rating of medium with a CVSS score of 4.3.
How does CVE-2022-0833 impact the Church Admin WordPress plugin?
CVE-2022-0833 allows unauthenticated attackers to repeatedly request the "refresh-backup" action and access publicly accessible temporary files.
How can I fix CVE-2022-0833?
To fix CVE-2022-0833, update the Church Admin WordPress plugin to version 3.4.135 or later.
Where can I find more information about CVE-2022-0833?
You can find more information about CVE-2022-0833 at the following reference link: [CVE-2022-0833](https://wpscan.com/vulnerability/b2c7c1e8-d72c-4b1e-b5cb-dc2a6538965d)