CVE-2024-13771 Details
Description
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This makes it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim.
An authentication bypass vulnerability has been identified in the Civi - Job Board & Freelance Marketplace WordPress Theme, affecting all versions through 2.1.4. The vulnerability arises from inadequate user validation before password changes, allowing unauthenticated attackers to reset the passwords of any users, including administrators, if they know the username.
There is no known patch available for this vulnerability. Users are advised to review the vulnerability details and consider uninstalling the affected theme.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| uxper civi | <= 2.1.4 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | CVE Modified | [email protected] |
| Mar 28, 2025 | Reanalysis | [email protected] |
| Mar 27, 2025 | Initial Analysis | [email protected] |
| Mar 14, 2025 | New CVE Received | [email protected] |