CVE-2023-30782: WordPress Church Admin Plugin <= 3.7.5 is vulnerable to Cross Site Scripting (XSS)
Published Aug 16, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions.
Affected Software
1 affected component
Churchadminplugin Church Admin Wordpress<=3.7.5
Remediation
Information
Update to 3.7.6 or a higher version.
Event History
Aug 16, 2023
CVE Published
via MITRE·09:43 AM
Data Sourced
via MITRE·09:43 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-30782?
CVE-2023-30782 has a severity rating that indicates it could allow unauthenticated attackers to execute scripts in the context of the affected user.
2
How do I fix CVE-2023-30782?
To fix CVE-2023-30782, update the Andy Moyle Church Admin plugin to version 3.7.6 or later.
3
What kind of attack can CVE-2023-30782 facilitate?
CVE-2023-30782 can facilitate reflected Cross-Site Scripting (XSS) attacks.
4
Which versions of the Church Admin plugin are affected by CVE-2023-30782?
Versions of the Church Admin plugin up to and including 3.7.5 are affected by CVE-2023-30782.
5
Is authentication required to exploit CVE-2023-30782?
No, exploitation of CVE-2023-30782 does not require user authentication.