{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-08T14:22:56.971","vulnerabilities":[{"cve":{"id":"CVE-2024-13771","sourceIdentifier":"security@wordfence.com","published":"2025-03-14T12:15:13.693","lastModified":"2026-04-08T18:20:16.583","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This makes it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim."},{"lang":"es","value":"El complemento Civi - Job Board &amp; Freelance Marketplace WordPress Theme para WordPress es vulnerable a la omisión de la autenticación en todas las versiones hasta la 2.1.4 incluida. Esto se debe a la falta de validación del usuario antes de cambiar la contraseña. Esto permite que atacantes no autenticados cambien la contraseña de usuarios arbitrarios, incluidos administradores, si conocen el nombre de usuario de la víctima."}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-288"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:uxper:civi:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"2.1.4","matchCriteriaId":"FF63574D-F8E6-4F90-8397-9E27E3E7239A"}]}]}],"references":[{"url":"https://themeforest.net/item/civi-job-board-wordpress-theme/42770817","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/5ab2c74d-b83b-40ea-951c-83aeb76a7515?source=cve","source":"security@wordfence.com","tags":["Third Party Advisory"]}]}}]}