Church Admin
Church Admin has 28 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; all 28 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 6 high. 2024 was the busiest year with 15 disclosures.
The most common weakness is Cross-Site Scripting, behind 8 of the records (29%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).
Every one of the 28 issues recorded for Church Admin has a vendor fix available, so running the current release closes all known holes.
17 independent researchers contributed these findings, most of them (4) reported by Peng Zhou. Church Admin is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-37418Church Admin <= 4.4.6 - Authenticated (Subscriber+) Arbitrary File Upload
Read the full analysisVulnerability Records

Church Admin
Author
andy_moyle
This plugin is for church wordpress sites to give you a membership database, church calendar and sermon podcasting tools. There is a premium version that adds many more modules like service scheduling, event ticketing and a church app. Sign up for our email list to get a detailed PDF manual Plugin site Compatible with Elementor and provides Elementor widgets, tested to v3.25 FREE VERSION Church Membership database Integrate newcomers with customisable registration form and follow up flows Calendar for church diary Sermon podcasting Customisable Church Directory with full privacy settings. PREMIUM VERSION Adds scheduling, communication tools, ministries, giving, pastoral visitation, an app and more.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C