CVE-2024-53795: WordPress Church Admin plugin <= 5.0.8 - Broken Access Control vulnerability
Published Dec 6, 2024
·Updated
Missing Authorization vulnerability in andymoyle Church Admin church-admin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Church Admin: from n/a through <= 5.0.8.
Affected Software
1 affected component
Andy Moyle Church Admin<=5.0.8
Remediation
Information
Update the WordPress Church Admin plugin to the latest available version (at least 5.0.9).
Event History
Dec 6, 2024
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-53795?
CVE-2024-53795 has been classified as a missing authorization vulnerability that may allow unauthorized access to sensitive functionality.
2
How do I fix CVE-2024-53795?
To address CVE-2024-53795, upgrade to version 5.0.9 or later of the affected Church Admin software.
3
What are the affected versions for CVE-2024-53795?
CVE-2024-53795 affects versions of Church Admin up to and including 5.0.8.
4
What functionality is impacted by CVE-2024-53795?
CVE-2024-53795 allows access to functionality that is not properly constrained by Access Control Lists (ACLs).
5
Who is affected by CVE-2024-53795?
Users of Andy Moyle Church Admin and WordPress Church Admin plugin from n/a through version 5.0.8 are affected by CVE-2024-53795.