Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total3
Critical1
High1
Medium1
Reset
Showing 1-3 of 3 records
Threat Entry Updated 2025-03-27

CVE-2024-13773 - Civi Plugin

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via hard-coded credentials. This makes it possible for unauthenticated attackers to extract sensitive data including LinkedIn client and secret keys.

PLUGIN Civi

CVE-2024-13773

HIGH CVSS 7.3 2025-03-14
Threat Entry Updated 2025-03-28

CVE-2024-13771 - Civi Plugin

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This makes it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim.

PLUGIN Civi

CVE-2024-13771

CRITICAL CVSS 9.8 2025-03-14
Threat Entry Updated 2025-06-17

CVE-2024-13772 - Civi Plugin

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.6.1. This is due to a lack of password randomization and user validation through the fb_ajax_login_or_register and google_ajax_login_or_register actions. This makes it possible for unauthenticated attackers to login as any user as long as they have access to the email.

PLUGIN Civi

CVE-2024-13772

MEDIUM CVSS 5.6 2025-03-14
Scroll to top