Critical Authentication Bypass Flaw in JobMonster WordPress Theme Exploited

Critical Authentication Bypass Flaw in JobMonster WordPress Theme Exploited

First seen 2 Dec 2025, 18:33 UTC BleepingcomputerTechzine.EuScmagazine 33.9

Article Content

Browse articles
ThreatCluster

Hackers are exploiting a critical authentication bypass vulnerability (CVE-2025-5397) in the JobMonster WordPress theme, allowing unauthorized access to administrative accounts. This flaw, rated 9.8 in severity, poses risks such as data theft and impersonation scams. The theme, developed by NooThemes, has over 5,600 sales on the ThemeForest marketplace.