A Missing Authorization vulnerability was found in the Church Admin plugin. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels and affects Church Admin versions from n/a through 5.0.30. The vulnerability has been assigned a CVSS score of 5.3 and a severity of MEDIUM. Users of Church Admin plugin versions up to 5.0.30 should be aware of this vulnerability and take necess [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the Emergency Password Reset plugin up to version 8.0. This issue allows attackers to trick users into performing unintended actions on the website. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. Users of the Emergency Password Reset plugin should take immediate action to protect their sites.