A vulnerability classified as problematic has been found in ChurchCRM up to 7.3.1. This affects an unknown part of the file FundRaiserDelete.php. Performing a manipulation results in cross-site request forgery.

This vulnerability was named CVE-2026-44548. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.