The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-54059 The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of randomization of a password created during Single Sign-On via Google or Facebook. This makes it possible for unauthenticated attackers to change the password of arbitrary Candidate-level users if the attacker knows the username assigned to the victim during account creation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00042}

epss

{'score': 0.00052}


Tue, 17 Jun 2025 18:30:00 +0000


Tue, 17 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Description The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of randomization of a password created during Single Sign-On via Google or Facebook. This makes it possible for unauthenticated attackers to change the password of arbitrary Candidate-level users if the attacker knows the username assigned to the victim during account creation. The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.
Title Civi - Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Authentication Bypass via Non-Randomized Password for SSO Accounts Civi - Job Board & Freelance Marketplace WordPress Theme <= 2.1.6.1 - Authentication Bypass
References

Fri, 28 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Uxper
Uxper civi
CPEs cpe:2.3:a:yxper:civi:*:*:*:*:*:wordpress:*:* cpe:2.3:a:uxper:civi:*:*:*:*:*:wordpress:*:*
Vendors & Products Yxper
Yxper civi
Uxper
Uxper civi

Thu, 27 Mar 2025 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Yxper
Yxper civi
Weaknesses CWE-306
CPEs cpe:2.3:a:yxper:civi:*:*:*:*:*:wordpress:*:*
Vendors & Products Yxper
Yxper civi

Fri, 14 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Mar 2025 11:30:00 +0000

Type Values Removed Values Added
Description The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of randomization of a password created during Single Sign-On via Google or Facebook. This makes it possible for unauthenticated attackers to change the password of arbitrary Candidate-level users if the attacker knows the username assigned to the victim during account creation.
Title Civi - Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Authentication Bypass via Non-Randomized Password for SSO Accounts
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-06-17T18:05:41.908Z

Reserved: 2025-01-28T17:18:28.551Z

Link: CVE-2024-13772

cve-icon Vulnrichment

Updated: 2025-03-14T12:35:23.536Z

cve-icon NVD

Status : Modified

Published: 2025-03-14T12:15:13.907

Modified: 2025-06-17T18:15:24.887

Link: CVE-2024-13772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.