CVE-2026-66478: WordPress Church Admin plugin <= 5.1.1 - SQL Injection vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
Affected Software
1 affected component
WordPress Church Admin plugin<=5.1.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Church Admin Pluginto a version that resolves this vulnerability.Fixed in 5.1.2
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66478?
The severity of CVE-2026-66478 is critical with a CVSS score of 9.3.
2
What type of vulnerability is identified in CVE-2026-66478?
CVE-2026-66478 identifies an unauthenticated SQL Injection vulnerability in the WordPress Church Admin plugin.
3
How do I fix CVE-2026-66478?
To fix CVE-2026-66478, update the WordPress Church Admin plugin to version 5.1.2 or later.
4
Which versions of the WordPress Church Admin plugin are affected by CVE-2026-66478?
CVE-2026-66478 affects versions of the WordPress Church Admin plugin up to and including 5.1.1.
5
What impact does CVE-2026-66478 have on my website?
Exploiting CVE-2026-66478 could allow an attacker to perform unauthorized SQL queries on your database.