Impact
The Church Admin plugin for WordPress contains a missing authorization flaw that allows users to access features and pages that should be restricted to administrators. This defect can enable an attacker to gain elevated privileges within the WordPress site, potentially compromising the confidentiality, integrity, and availability of site content and configuration. The weakness is identified as CWE‑862, Missing Authorization.
Affected Systems
All releases of the Church Admin plugin authored by andy_moyle, from its initial release through version 5.0.30, are vulnerable. WordPress installations that have installed or continue to use any of these affected plugin versions are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, via the WordPress admin interface, where an attacker may exploit inadequate access controls to navigate to protected plugin pages and reach privileged functionality.
OpenCVE Enrichment