CVE-2024-13771
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Published Mar 14, 2025
Updated: Mar 28, 2025
CWE ID 306
CWE ID 288
Summary
CVE-2024-13771 is a vulnerability affecting the Civi- Job Board & Freelance Marketplace WordPress Theme plugin. This issue allows unauthenticated attackers to bypass authentication and change the password of any user, including administrators, if the attacker knows the victim's username. The vulnerability arises due to the plugin's lack of user validation before password changes, making it essential for users to update to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.