Vulnerability Description
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This makes it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uxper | Civi | <= 2.1.4 |
Related Weaknesses (CWE)
References
- https://themeforest.net/item/civi-job-board-wordpress-theme/42770817
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5ab2c74d-b83b-40ea-951Third Party Advisory
FAQ
What is CVE-2024-13771?
CVE-2024-13771 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user vali...
How severe is CVE-2024-13771?
CVE-2024-13771 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-13771?
Check the references section above for vendor advisories and patch information. Affected products include: Uxper Civi.