Vulnerabilities > CVE-2024-13773 - Use of Hard-coded Cryptographic Key vulnerability in Uxper Civi

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
uxper
CWE-321

Summary

The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via hard-coded credentials. This makes it possible for unauthenticated attackers to extract sensitive data including LinkedIn client and secret keys.

Vulnerable Configurations

Part Description Count
Application
Uxper
1

Common Weakness Enumeration (CWE)