CVE-2023-34021: WordPress Church Admin Plugin <= 3.7.29 is vulnerable to Cross Site Scripting (XSS)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.29 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Andy Moyle Church Admin pluginto a version that resolves this vulnerability.Fixed in 3.7.30
Event History
Frequently Asked Questions
What is CVE-2023-34021?
CVE-2023-34021 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in the Andy Moyle Church Admin plugin version 3.7.29 and below.
How does CVE-2023-34021 affect the Church Admin plugin?
CVE-2023-34021 allows remote attackers to inject malicious scripts into web pages viewed by the plugin's users, potentially leading to session hijacking or unauthorized actions.
What is the severity level of CVE-2023-34021?
CVE-2023-34021 has a severity level of 6.1 (High).
How can I fix CVE-2023-34021?
To fix CVE-2023-34021, it is recommended to update the Andy Moyle Church Admin plugin to version 3.7.30 or higher, as it contains a patch for the vulnerability.
What is the Common Weakness Enumeration (CWE) associated with CVE-2023-34021?
The Common Weakness Enumeration (CWE) associated with CVE-2023-34021 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').