Impact
The Church Admin plugin for WordPress contains an improper neutralization of special elements in an SQL command, allowing an attacker to inject arbitrary SQL through unvalidated input. This vulnerability can enable reading, modifying, or deleting database records, leading to data loss, confidentiality breach, or further compromise. The CVSS score of 9.3 indicates severe severity, with the weakness classified as CWE‑89.
Affected Systems
Security audits should focus on instances of the Church Admin plugin that are at or below version 5.0.18. The affected product is the WordPress plugin named Church Admin developed by Andy Moyle. Any WordPress site using this plugin within the specified version range is vulnerable.
Risk and Exploitability
The EPSS score is less than 1%, suggesting a low current exploitation rate, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, given the high CVSS score, the impact could be catastrophic if exploited. The attack vector is likely web‑based, where an attacker sends crafted requests to plugin endpoints that include unsanitized user input. While the description does not specify authentication requirements, inference points to a potential unauthenticated or low‑privilege access scenario, making the vulnerability particularly dangerous.
OpenCVE Enrichment
EUVD