Civi Job Board and Freelance Marketplace WordPress Theme Authentication Bypass Vulnerability

Vulnerability

An authentication bypass vulnerability has been identified in the Civi - Job Board & Freelance Marketplace WordPress Theme, affecting all versions through 2.1.6.1. The vulnerability arises from inadequate password randomization and user validation in the fb_ajax_login_or_register and google_ajax_login_or_register actions. This flaw allows unauthenticated attackers to log in as any user, provided they have access to the user's email.

Impact

Exploitation of this vulnerability allows for unauthorized access to user accounts, potentially leading to further actions under the guise of the compromised user.

Remediation

Users are advised to update to version 2.1.6.3 or a newer patched version.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.