← WordPress Vulnerabilities
WordPress security by component

Civi

Civi is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: civi

CVE-2026-65476: Civi: A security weakness

Civi is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.4.

PublishedJul 23, 2026
Known safe version> 2.2.4
Safe version
Jul 23, 2026 CVE-2026-65476
Civi: A security weakness
Civi is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.2.4.
> 2.2.4
CVE5.3
NVDPending
Mar 14, 2025 CVE-2024-13773
Civi - Job Board & Freelance Marketplace: Sensitive information exposure
Civi - Job Board & Freelance Marketplace is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE7.3
NVD7.5
Mar 14, 2025 CVE-2024-13772
Civi - Job Board & Freelance Marketplace: Privilege escalation or authentication bypass
Civi - Job Board & Freelance Marketplace is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE5.6
NVD5.9
Mar 14, 2025 CVE-2024-13771
Civi - Job Board & Freelance Marketplace: Privilege escalation or authentication bypass
Civi - Job Board & Freelance Marketplace is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD5.9