S4E just found an informational finding from web application firewall (waf) detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2015-4127 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Church Admin plugin for WordPress affects v. before 0.810.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-4127
4.3
CVSS

Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Church Admin plugin for WordPress is a tool designed to assist churches in managing their congregation and events. It allows users to create custom registration forms for events, manage attendees, and keep track of giving records. This plugin is particularly popular among churches, which use it to streamline their administrative processes and improve their overall organization.

However, despite its popularity, the Church Admin plugin is not without its vulnerabilities. One such vulnerability is the CVE-2015-4127, which allows remote attackers to inject arbitrary web scripts or HTML into the address parameter. Such an attack can allow the attacker to hijack the user's browser, redirect them to malicious sites, or steal their personal information. 

If this vulnerability is exploited, it can lead to a wide range of consequences. For example, if a church administration tool is compromised, the attacker could potentially access sensitive information such as giving records, pastoral notes, and other confidential data. Similarly, if a registration form is compromised, attackers could potentially steal the personal information of church members and attendees, including their names, email addresses, phone numbers, and more.

At s4e.io, we offer a powerful platform that can help users detect and mitigate potential vulnerabilities in their digital assets. By leveraging our pro features, users can quickly and easily identify any security issues and take action to protect their online assets. So if you're using the Church Admin plugin for WordPress, be sure to check out our platform and keep your digital assets safe and secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it's crucial for churches to take precautions such as:

  • Updating to the latest version of the Church Admin plugin
  • Ensuring that all plugins and themes are up to date
  • Using a reliable security plugin that can scan for vulnerabilities and prevent attacks in real-time

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-4127 scanner - Cross-Site Scripting (XSS) vulnerability in Church Admin plugin for WordPress | S4E