Church Admin

Church Admin has 28 disclosed vulnerabilities in the WordSec catalog, reported between 2015 and 2026; all 28 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 6 high. 2024 was the busiest year with 15 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (29%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).

Every one of the 28 issues recorded for Church Admin has a vendor fix available, so running the current release closes all known holes.

17 independent researchers contributed these findings, most of them (4) reported by Peng Zhou. Church Admin is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891031.01.2011Today22.05.20156.1Church Admin < 0.810 - Stored Cross-Site Scripting CVSS 6.1 · 22.05.201514.02.20188.8Church Admin < 1.2550 - Cross-Site Request Forgery CVSS 8.8 · 14.02.201807.03.20224.3Church Admin <= 3.4.134 - Cross-Site Request Forgery leading to Plugin Backup Disclosure CVSS 4.3 · 07.03.202218.04.20236.1Church Admin <= 3.7.5 - Reflected Cross-Site Scripting CVSS 6.1 · 18.04.202313.06.20236.1Church Admin <= 3.7.29 - Reflected Cross-Site Scripting CVSS 6.1 · 13.06.202326.07.20235.5Church Admin <= 3.7.56 - Server-Side Request Forgery via church_admin_import_csv CVSS 5.5 · 26.07.202325.03.20246.4Church Admin <= 4.1.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via meta-text CVSS 6.4 · 25.03.20246.4Church Admin <= 4.0.26 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode CVSS 6.4 · 25.03.202426.03.20248.8Church Admin <= 4.0.27 - Authenticated (Contributor+) SQL Injection CVSS 8.8 · 26.03.202428.03.20244.3Church Admin <= 4.1.18 - Missing Authorization CVSS 4.3 · 28.03.20244.3Church Admin <= 4.1.7 - Cross-Site Request Forgery CVSS 4.3 · 28.03.202405.04.20248.8Church Admin <= 4.1.5 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 05.04.20244.3Church Admin <= 4.1.6 - Missing Authorization CVSS 4.3 · 05.04.202411.04.20244.3Church Admin <= 4.0.27 - Cross-Site Request Forgery CVSS 4.3 · 11.04.202409.05.20244.3Church Admin <= 4.1.32 - Cross-Site Request Forgery CVSS 4.3 · 09.05.202430.05.20245.5Church Admin <= 4.3.6 - Authenticated (Admin+) Server-Side Request Forgery CVSS 5.5 · 30.05.202417.06.20246.4Church Admin <= 4.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 17.06.202428.06.20245.3Church Admin <= 4.4.4 - Missing Authorization CVSS 5.3 · 28.06.202404.07.20248.8Church Admin <= 4.4.6 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 04.07.202424.10.20246.1Church Admin < 5.0.0 - Reflected Cross-Site Scripting CVSS 6.1 · 24.10.202402.12.20245.3Church Admin <= 5.0.8 - Missing Authorization CVSS 5.3 · 02.12.202413.03.20257.5Church Admin <= 5.0.18 - Unauthenticated SQL Injection CVSS 7.5 · 13.03.202516.04.20256.4Church Admin <= 5.0.23 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 16.04.20255.3Church Admin <= 5.0.9 - Unauthenticated Information Disclosure CVSS 5.3 · 16.04.202522.08.20255.3Church Admin <= 5.0.26 - Missing Authorization CVSS 5.3 · 22.08.202516.01.20262.2Church Admin <= 5.0.28 - Authenticated (Administrator+) Blind Server-Side Request Forgery via 'audio_url' Parameter CVSS 2.2 · 16.01.202603.08.20264.3Church Admin <= 5.0.30 - Missing Authorization CVSS 4.3 · 03.08.202610.08.20267.5Church Admin <= 5.1.1 - Unauthenticated SQL Injection CVSS 7.5 · 10.08.2026

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

28

Get automatic notifications for all Church Admin vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2024-37418

Church Admin <= 4.4.6 - Authenticated (Subscriber+) Arbitrary File Upload

Read the full analysis

Vulnerability Records

28 records
Church Admin banner
Latestv5.1.2

Church Admin

andy_moyle

Author

andy_moyle

4.7(17)
94/100
Last Updated
2026-07-27 (2mo ago)
Active Installs
900+
Downloads
462,927
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2011-01-31 (16y ago)

This plugin is for church wordpress sites to give you a membership database, church calendar and sermon podcasting tools. There is a premium version that adds many more modules like service scheduling, event ticketing and a church app. Sign up for our email list to get a detailed PDF manual Plugin site Compatible with Elementor and provides Elementor widgets, tested to v3.25 FREE VERSION Church Membership database Integrate newcomers with customisable registration form and follow up flows Calendar for church diary Sermon podcasting Customisable Church Directory with full privacy settings. PREMIUM VERSION Adds scheduling, communication tools, ministries, giving, pastoral visitation, an app and more.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C