CVE-2024-35637: WordPress Church Admin plugin <= 4.3.6 - Server Side Request Forgery (SSRF) vulnerability
Published Jun 3, 2024
·Updated
Server-Side Request Forgery (SSRF) vulnerability in andymoyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.3.6.
Affected Software
2 affected components
WordPress Church Admin<=4.3.6
Church Admin Project Church Admin Wordpress<4.4.0
Remediation
Event History
Jun 3, 2024
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35637?
CVE-2024-35637 has a medium severity rating due to its potential for Server-Side Request Forgery (SSRF) attacks.
2
How do I fix CVE-2024-35637?
To fix CVE-2024-35637, update the Church Admin plugin to a version greater than 4.3.6.
3
What software is affected by CVE-2024-35637?
CVE-2024-35637 affects the Church Admin plugin on WordPress versions up to and including 4.3.6.
4
What are the risks associated with CVE-2024-35637?
The risks of CVE-2024-35637 include unauthorized access to internal resources and potential data exposure.
5
Is CVE-2024-35637 actively being exploited?
Currently, there is no public information indicating that CVE-2024-35637 is actively being exploited in the wild.