CVE-2024-30193: WordPress Church Admin plugin <= 4.1.17 - Stored Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andymoyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.17.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30193?
CVE-2024-30193 is classified as a critical severity vulnerability due to its potential for Stored Cross-Site Scripting (XSS).
How do I fix CVE-2024-30193?
To fix CVE-2024-30193, update Andy Moyle Church Admin to the latest version beyond 4.1.17, or apply patches as provided by the vendor.
What impact does CVE-2024-30193 have on my website?
CVE-2024-30193 can allow attackers to inject malicious scripts into web pages viewed by users, leading to data theft and unauthorized actions.
Which versions of Church Admin are affected by CVE-2024-30193?
CVE-2024-30193 affects Andy Moyle Church Admin versions up to and including 4.1.17.
Is CVE-2024-30193 a common vulnerability?
CVE-2024-30193, involving Stored XSS, is a common type of vulnerability that can exist in web applications if user input is not properly validated.