Description
Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Church Admin plugin for WordPress contains a missing authorization flaw that allows users to access features and pages that should be restricted to administrators. This defect can enable an attacker to gain elevated privileges within the WordPress site, potentially compromising the confidentiality, integrity, and availability of site content and configuration. The weakness is identified as CWE‑862, Missing Authorization.

Affected Systems

All releases of the Church Admin plugin authored by andy_moyle, from its initial release through version 5.0.30, are vulnerable. WordPress installations that have installed or continue to use any of these affected plugin versions are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, via the WordPress admin interface, where an attacker may exploit inadequate access controls to navigate to protected plugin pages and reach privileged functionality.

Generated by OpenCVE AI on August 1, 2026 at 10:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Church Admin plugin to the latest released version that addresses the access control defect; if a newer version is not yet publicly available, plan to apply the vendor’s patch as soon as it is released.
  • Remove or disable the Church Admin plugin entirely if an immediate update cannot be performed, thereby eliminating the exposure from the plugin’s code.
  • Review and tighten WordPress user role configurations to ensure that only administrators have access to Church Admin plugin pages, limiting potential misuse of the vulnerable functionality.

Generated by OpenCVE AI on August 1, 2026 at 10:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Andymoyle
Andymoyle church Admin
Wordpress
Wordpress wordpress
Vendors & Products Andymoyle
Andymoyle church Admin
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.
Title WordPress Church Admin plugin <= 5.0.30 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Andymoyle Church Admin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:19:36.054Z

Reserved: 2026-07-13T06:14:00.716Z

Link: CVE-2026-61983

cve-icon Vulnrichment

Updated: 2026-07-13T14:19:30.412Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses