Stored Cross-Site Scripting Vulnerability in Church Admin Plugin for WordPress
CVE-2026-94421
6.4MEDIUM
What is CVE-2026-94421?
The Church Admin plugin for WordPress has a vulnerability that allows authenticated attackers with subscriber-level access or higher to exploit the 'email' parameter. Due to inadequate input sanitization and output escaping, attackers can inject arbitrary web scripts into pages, leading to potential execution whenever a user accesses the compromised content. This highlights the importance of implementing robust input validation mechanisms to safeguard against such attacks.
Affected Version(s)
Church Admin 0 <= 5.1.2