CVE-2024-13772 MEDIUM

CVE-2024-13772: Civi - Job Board & Freelance Marketplace WordPress Theme <= 2.1.6.1 - Authentication Bypass

Vendor Uxper
Product Civi - Job Board & Freelance Marketplace WordPress Theme
Weakness CWE-288
Published March 14, 2025
Last update April 8, 2026

CVSS base score

5.6/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.

Explanation of Vulnerability in Simple Terms

02Summary

The Civi Job Board & Freelance Marketplace WordPress theme contains an authentication bypass vulnerability in versions up to 2.1.6.1. An attacker can exploit this flaw to gain unauthorized access without valid credentials. The vulnerability requires specific network conditions but does not require user interaction. Affected sites should update immediately.

What an attacker can do

03Attacker Capabilities

Bypass authentication and gain unauthorized access to the site without valid credentials.

Potential impact on your site

04Site Impact

Unauthorized users may access restricted areas, read sensitive data, or modify site content depending on the account privileges they obtain.

Conditions required to exploit

05Prerequisites

Network access to the site; no user interaction or authentication required, but attack complexity is high.

Key dates

06Disclosure timeline

March 14, 2025 CVE published
April 8, 2026 Record updated