Critical Authentication Bypass Flaw Exploited in JobMonster WordPress Theme

Critical Authentication Bypass Flaw Exploited in JobMonster WordPress Theme

First seen 23 Nov 2025, 03:35 UTC Techzine.Eu 34.7

Article Content

Browse articles
ThreatCluster

Hackers are exploiting a critical authentication bypass vulnerability (CVE-2025-5397) in the JobMonster WordPress theme, allowing unauthorized access to administrative accounts. This flaw, rated 9.8 in severity, poses risks such as the theft of sensitive data and impersonation scams. The theme, developed by NooThemes, has over 5,600 sales on the ThemeForest marketplace.