Civi Job Board and Freelance Marketplace WordPress Theme Authentication Bypass Vulnerability
Vulnerability
An authentication bypass vulnerability has been identified in the Civi - Job Board & Freelance Marketplace WordPress Theme, affecting all versions through 2.1.6.1. The vulnerability arises from inadequate password randomization and user validation in the fb_ajax_login_or_register and google_ajax_login_or_register actions. This flaw allows unauthenticated attackers to log in as any user, provided they have access to the user's email.
Impact
Exploitation of this vulnerability allows for unauthorized access to user accounts, potentially leading to further actions under the guise of the compromised user.
Remediation
Users are advised to update to version 2.1.6.3 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
