First published: Fri May 17 2024(Updated: )
Missing Authorization vulnerability in Andy Moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through 4.1.6.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Andy Moyle Church Admin | <=4.1.6 | |
WordPress Church Admin plugin | <=4.1.6 |
Update to 4.1.7 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31281 is classified as a missing authorization vulnerability that can lead to exploitation of incorrectly configured access control security levels.
To fix CVE-2024-31281, ensure that access control settings are properly configured and update Church Admin to version 4.1.7 or later.
CVE-2024-31281 affects Church Admin versions up to and including 4.1.6.
The vendor of the affected software is Andy Moyle for Church Admin.
Yes, CVE-2024-31281 can potentially be exploited remotely due to the missing authorization in access control.