Critical Authentication Bypass Flaw Exploited in JobMonster WordPress Theme

Critical Authentication Bypass Flaw Exploited in JobMonster WordPress Theme

First seen 5 Nov 2025, 17:08 UTC BleepingcomputerScmagazine 52.1

Article Content

Browse articles
ThreatCluster

Attackers are exploiting a critical authentication bypass vulnerability (CVE-2025-5397) in the JobMonster WordPress theme, which allows unauthorized access to administrative accounts. This flaw, rated 9.8 in severity, could lead to the theft of sensitive data, including résumés and recruiter information, and facilitate impersonation scams. The JobMonster theme, developed by NooThemes, has over 5,600 sales on the ThemeForest marketplace.