CVE-2024-13772 Details
Description
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.
An authentication bypass vulnerability has been identified in the Civi - Job Board & Freelance Marketplace WordPress Theme, affecting all versions through 2.1.6.1. The vulnerability arises from inadequate password randomization and user validation in the fb_ajax_login_or_register and google_ajax_login_or_register actions. This flaw allows unauthenticated attackers to log in as any user, provided they have access to the user's email.
Users are advised to update to version 2.1.6.3 or a newer patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| uxper civi | <= 2.1.4 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2025 | CVE Modified | [email protected] |
| Mar 28, 2025 | Reanalysis | [email protected] |
| Mar 27, 2025 | Initial Analysis | [email protected] |
| Mar 14, 2025 | New CVE Received | [email protected] |