PT-2025-11254 · WordPress · Civi - Job Board & Freelance Marketplace Wordpress Theme

Lucio Sá

·

Published

2025-03-14

·

Updated

2026-04-08

·

CVE-2024-13771

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Civi - Job Board & Freelance Marketplace WordPress Theme plugin versions up to, and including, 2.1.4
Description: The issue is due to a lack of user validation before changing a password, making it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim.
Recommendations: For versions up to, and including, 2.1.4, update to a version that includes the fix for this issue to prevent authentication bypass. As a temporary workaround, consider restricting access to password change functionality until a patch is available.

Fix

Authentication Bypass Using an Alternate Path or Channel

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-13771

Affected Products

Civi - Job Board & Freelance Marketplace Wordpress Theme