Skip to content
Critical Authentication Bypass Flaw in JobMonster WordPress Theme Exploited

Critical Authentication Bypass Flaw in JobMonster WordPress Theme Exploited

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Hackers are exploiting a critical authentication bypass vulnerability (CVE-2025-5397) in the JobMonster WordPress theme, allowing unauthorized access to administrative accounts. This flaw, rated 9.8 in severity, poses risks such as data theft and impersonation scams. The theme, developed by NooThemes, has over 5,600 sales on the ThemeForest marketplace.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (3)

Following this threat?

Track CVE-2025-11533 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed