Sceawere
Vulnerability Detail
CVE-2026-94421UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Church Admin Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- andy_moyle
- Product
- Church Admin
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Church Admin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 5.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T06:16:45.043Z",
"pubdate": "2026-10-10T06:16:45.043Z",
"executiveSummary": "The Church Admin plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and output escaping. This flaw exists within the 'email' parameter and affects all versions up to and including 5.1.2.\nThe vulnerability allows authenticated attackers, possessing at least subscriber-level privileges, to inject arbitrary JavaScript or HTML payloads into the application. When a victim, such as an administrator or another user, navigates to the affected page, the malicious script executes within the context of their session.\nThe primary risk implications involve the potential for session hijacking, unauthorized actions performed on behalf of the victim, and the exfiltration of sensitive information. Because the script is stored persistently in the database, the impact is significant, potentially leading to full account takeover or site compromise. Successful exploitation requires an attacker to possess valid WordPress credentials with a minimum of subscriber access, which is commonly granted in membership-based environments. Organizations utilizing this plugin should prioritize updating to a version where this input is correctly sanitized or implementing temporary restrictions on user input if a patch is unavailable.",
"technicalDetails": "The vulnerability originates from the application's failure to sanitize and validate user-supplied input processed through the 'email' parameter before storing it in the database. Furthermore, the application fails to perform adequate output encoding when rendering this data in the browser, allowing the browser to interpret malicious strings as executable code.\nThe root cause is a deficiency in the input handling logic of the Church Admin plugin. When a user submits an email address via the affected interface, the application accepts the input without filtering out JavaScript event handlers or script tags. Consequently, an attacker can supply a payload such as <script>alert('XSS')</script> or event-based triggers like <img src=x onerror=alert(1)>.\nThe exploitation flow is as follows: 1) An authenticated attacker with subscriber-level permissions navigates to the input field associated with the 'email' parameter. 2) The attacker injects a malicious payload into the parameter. 3) The plugin processes the request and persists the unsanitized payload into the WordPress database. 4) When an unsuspecting user or administrator accesses the page where the stored 'email' value is rendered, the application serves the malicious script to the victim's browser without escaping special characters. 5) The browser parses the script and executes it within the security context of the victim's session.\nThis vulnerability is particularly dangerous because it facilitates persistent exploitation. Unlike reflected XSS, which requires enticing a user to click a specific link, Stored XSS executes automatically upon the victim loading the compromised page. The post-exploitation impact includes the ability to steal authentication cookies, perform unauthorized administrative actions, redirect users to malicious domains, or deploy further client-side attacks.\nSince the execution occurs within the victim's browser session, any action the victim is authorized to perform can be replicated by the malicious script. If an administrator views the injected page, the attacker can leverage the admin's session to modify site settings, create new users, or further compromise the WordPress environment. This vulnerability affects all versions of the Church Admin plugin through 5.1.2. The lack of strict content security policies (CSP) or robust input sanitization routines in the vulnerable components directly contributes to this security breakdown."
}