First published: Fri Mar 29 2024(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.7.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Andy Moyle Church Admin | <=4.1.7 | |
WordPress Church Admin | <=4.1.7 |
Update to 4.1.8 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30493 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions being performed on behalf of a user.
To mitigate CVE-2024-30493, upgrade Andy Moyle Church Admin and the WordPress Church Admin plugin to the latest version beyond 4.1.7.
CVE-2024-30493 affects versions of Church Admin up to and including 4.1.7.
If exploited, CVE-2024-30493 could allow an attacker to perform unauthorized actions on behalf of logged-in users without their consent.
CVE-2024-30493 impacts both the standalone Andy Moyle Church Admin application and the WordPress Church Admin plugin.