CVE-2024-13771

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Mar 14, 2025
Updated: Mar 28, 2025
CWE ID 306
CWE ID 288

Summary

CVE-2024-13771 is a vulnerability affecting the Civi- Job Board & Freelance Marketplace WordPress Theme plugin. This issue allows unauthenticated attackers to bypass authentication and change the password of any user, including administrators, if the attacker knows the victim's username. The vulnerability arises due to the plugin's lack of user validation before password changes, making it essential for users to update to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share