CVE-2024-13773

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via hard-coded credentials. This makes it possible for unauthenticated attackers to extract sensitive data including LinkedIn client and secret keys.
Configurations

Configuration 1 (hide)

cpe:2.3:a:uxper:civi:*:*:*:*:*:wordpress:*:*

History

27 Mar 2025, 01:07

Type Values Removed Values Added
Summary
  • (es) El complemento Civi - Job Board & Freelance Marketplace WordPress Theme para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 2.1.4 incluida, mediante credenciales codificadas. Esto permite a atacantes no autenticados extraer datos confidenciales, como claves de cliente y secretas de LinkedIn.
References () http://localhost:1337/wp-content/themes/civi/includes/class-init.php#L36 - () http://localhost:1337/wp-content/themes/civi/includes/class-init.php#L36 - Broken Link
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/e3499182-7501-4fec-a7c6-b66ae47533cd?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/e3499182-7501-4fec-a7c6-b66ae47533cd?source=cve - Third Party Advisory
First Time Uxper
Uxper civi
CWE CWE-798
CPE cpe:2.3:a:uxper:civi:*:*:*:*:*:wordpress:*:*

14 Mar 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-14 12:15

Updated : 2025-03-27 01:07


NVD link : CVE-2024-13773

Mitre link : CVE-2024-13773

CVE.ORG link : CVE-2024-13773


JSON object : View

Products Affected

uxper

  • civi
CWE
CWE-321

Use of Hard-coded Cryptographic Key

CWE-798

Use of Hard-coded Credentials