CVE-2024-34828: WordPress Church Admin plugin <= 4.1.32 - Cross Site Request Forgery (CSRF) vulnerability
Published May 10, 2024
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in andymoyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.32.
Affected Software
3 affected components
Andy Moyle Church Admin<=4.1.32
WordPress Church Admin plugin<=4.1.32
Church Admin Project Church Admin Wordpress<4.2.0
Remediation
Event History
May 10, 2024
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
DescriptionSeverityWeakness
May 14, 2024
Data Sourced
via NVD·03:39 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34828?
CVE-2024-34828 is classified as a Cross-Site Request Forgery (CSRF) vulnerability affecting the Andy Moyle Church Admin software.
2
How do I fix CVE-2024-34828?
To resolve CVE-2024-34828, upgrade the Andy Moyle Church Admin software to version 4.1.33 or later.
3
What versions of Church Admin are affected by CVE-2024-34828?
CVE-2024-34828 affects Church Admin versions up to and including 4.1.32.
4
Does CVE-2024-34828 affect the WordPress Church Admin plugin?
Yes, CVE-2024-34828 also impacts the WordPress Church Admin plugin versions up to and including 4.1.32.
5
What are the potential impacts of CVE-2024-34828?
CVE-2024-34828 can potentially allow an attacker to perform unauthorized actions on behalf of a logged-in user without their consent.