CVE-2024-31281: WordPress Church Admin plugin <= 4.1.6 - Broken Access Control vulnerability
Published May 17, 2024
·Updated
Missing Authorization vulnerability in andymoyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.6.
Affected Software
3 affected components
Andy Moyle Church Admin<=4.1.6
WordPress Church Admin<=4.1.6
Church Admin Project Church Admin Wordpress<4.1.7
Remediation
Event History
May 17, 2024
CVE Published
via MITRE·08:54 AM
Data Sourced
via MITRE·08:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31281?
CVE-2024-31281 is classified as a missing authorization vulnerability that can lead to exploitation of incorrectly configured access control security levels.
2
How do I fix CVE-2024-31281?
To fix CVE-2024-31281, ensure that access control settings are properly configured and update Church Admin to version 4.1.7 or later.
3
What versions of Church Admin are affected by CVE-2024-31281?
CVE-2024-31281 affects Church Admin versions up to and including 4.1.6.
4
Who is the vendor of the software affected by CVE-2024-31281?
The vendor of the affected software is Andy Moyle for Church Admin.
5
Can CVE-2024-31281 be exploited remotely?
Yes, CVE-2024-31281 can potentially be exploited remotely due to the missing authorization in access control.