What the vulnerability does
01Description
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.
Explanation of Vulnerability in Simple Terms
02Summary
The Civi Job Board & Freelance Marketplace WordPress theme contains an authentication bypass vulnerability in versions up to 2.1.6.1. An attacker can exploit this flaw to gain unauthorized access without valid credentials. The vulnerability requires specific network conditions but does not require user interaction. Affected sites should update immediately.
What an attacker can do
03Attacker Capabilities
Bypass authentication and gain unauthorized access to the site without valid credentials.
Potential impact on your site
04Site Impact
Unauthorized users may access restricted areas, read sensitive data, or modify site content depending on the account privileges they obtain.
Conditions required to exploit
05Prerequisites
Network access to the site; no user interaction or authentication required, but attack complexity is high.
Key dates
06Disclosure timeline
March 14, 2025
CVE published
April 8, 2026
Record updated