Executive brief
The Church Admin plugin for WordPress, which is used to manage church congregations and operations, contains a security flaw in its access control settings. An unauthorized user could exploit this to perform actions or modify data that should be restricted to administrators. This could lead to unauthorized changes in church records or administrative settings, potentially disrupting operations.
Technical details
A missing authorization vulnerability (CWE-862) exists in the andy_moyle Church Admin plugin for WordPress through version 5.0.30. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. A remote, unauthenticated attacker can exploit this vulnerability over the network to perform unauthorized modifications (Integrity impact). The issue is addressed in version 5.1.0.
Affected products
- andy_moyle Church Admin <= 5.0.30
Timeline
- 2026-07-13: advisory: NVD publication date
- 5.1.0: patched: Fixed in version 5.1.0