ZeroHour

CVE-2024-13772

CVSS 3.1
5.9 medium
EPSS
<1%p19
Published
()
Modified
Description

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.

Vendors
uxper
Products
civi
Ecosystems
WordPress
Weakness
CWE-288, CWE-306
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.