CVE-2024-30493: WordPress Church Admin plugin <= 4.1.7 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in andymoyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.7.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30493?
CVE-2024-30493 is classified as a Cross-Site Request Forgery (CSRF) vulnerability, which can lead to unauthorized actions being performed on behalf of a user.
How do I fix CVE-2024-30493?
To mitigate CVE-2024-30493, upgrade Andy Moyle Church Admin and the WordPress Church Admin plugin to the latest version beyond 4.1.7.
What versions are affected by CVE-2024-30493?
CVE-2024-30493 affects versions of Church Admin up to and including 4.1.7.
What impact can CVE-2024-30493 have on my site?
If exploited, CVE-2024-30493 could allow an attacker to perform unauthorized actions on behalf of logged-in users without their consent.
Is CVE-2024-30493 specific to a particular platform?
CVE-2024-30493 impacts both the standalone Andy Moyle Church Admin application and the WordPress Church Admin plugin.