Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin church-admin allows Stored XSS.This issue affects Church Admin: from n/a through <= 5.0.23.
Published: 2025-04-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Church Admin plugin performs inadequate neutralization of user input, enabling attackers to store malicious scripts that are subsequently injected into web pages rendered for other visitors. This stored XSS flaw can facilitate session hijacking, cookie theft, defacement, or delivery of additional malware, impacting the confidentiality, integrity, and availability of the website. The weakness is classified as CWE‑79.

Affected Systems

Vendor andy_moyle released the Church Admin plugin, which is affected in all releases from an unspecified base through version 5.0.23. Users operating any of these versions are potentially vulnerable.

Risk and Exploitability

The assessed CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Inferred attack vector requires an attacker to inject data through the plugin’s input mechanisms—likely through administrative or content‑editing privileges—before other users view the affected content. No documented exploit chain is available, though the stored nature of the flaw reduces the required attacker capability once the malicious script is present.

Generated by OpenCVE AI on April 30, 2026 at 22:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Church Admin to the latest release that removes the XSS issue.
  • If an upgrade is not yet available, disable or uninstall the plugin until a patched version is released.
  • Restrict the plugin’s input fields to trusted administrators and ensure any remaining content is properly escaped before display.

Generated by OpenCVE AI on April 30, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11310 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin allows Stored XSS. This issue affects Church Admin: from n/a through 5.0.23.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin allows Stored XSS. This issue affects Church Admin: from n/a through 5.0.23. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin church-admin allows Stored XSS.This issue affects Church Admin: from n/a through <= 5.0.23.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 16 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church Admin allows Stored XSS. This issue affects Church Admin: from n/a through 5.0.23.
Title WordPress Church Admin plugin <= 5.0.23 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:34.691Z

Reserved: 2025-04-16T06:24:54.680Z

Link: CVE-2025-39555

cve-icon Vulnrichment

Updated: 2025-04-16T13:21:36.276Z

cve-icon NVD

Status : Deferred

Published: 2025-04-16T13:15:48.153

Modified: 2026-04-23T15:29:46.947

Link: CVE-2025-39555

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:45:03Z

Weaknesses