CVE-2024-37440: WordPress Church Admin plugin <= 4.4.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in andymoyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.4.4.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37440?
CVE-2024-37440 is classified as a missing authorization vulnerability, which can lead to unauthorized access due to incorrectly configured access controls.
How do I fix CVE-2024-37440?
To fix CVE-2024-37440, ensure that proper access control configurations are applied and update to the latest secure version of Church Admin.
Which versions are affected by CVE-2024-37440?
CVE-2024-37440 affects all versions of Church Admin up to and including 4.4.4.
What are the risks associated with CVE-2024-37440?
The risks of CVE-2024-37440 include potential unauthorized access to sensitive data and functions within the application.
Is there a patch available for CVE-2024-37440?
Yes, a patch or update is available to address CVE-2024-37440; reviewing the latest releases from Andy Moyle is recommended.