PatchSiren

andy_moyle CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM andy_moyle CVE published 2026-07-13

CVE-2026-61983

A Missing Authorization vulnerability was found in the Church Admin plugin. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels and affects Church Admin versions from n/a through 5.0.30. The vulnerability has been assigned a CVSS score of 5.3 and a severity of MEDIUM. Users of Church Admin plugin versions up to 5.0.30 should be aware of this vulnerability and take necess [truncated]

MEDIUM Andy Moyle CVE published 2026-06-17

CVE-2024-35648

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the Emergency Password Reset plugin up to version 8.0. This issue allows attackers to trick users into performing unintended actions on the website. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Users of the Emergency Password Reset plugin should take immediate action to protect their sites.