Hackers exploit critical auth bypass flaw in JobMonster WordPress theme
A serious flaw in the JobMonster WordPress theme that permits administrator account hijacking under specific circumstances is the focus of threat actors.
Wordfence, a WordPress security company, discovered the malicious behavior after thwarting many exploit attempts against its customers during the previous 24 hours.
JobMonster is a premium WordPress theme developed by NooThemes that is utilized by candidate search tools, hiring and recruiting portals, and job listing websites. On Envato, the theme has sold over 5,500 copies.
The exploited vulnerability has a critical-severity score of 9.8 and is known as CVE-2025-5397. All theme versions up to 4.8.1 are affected by this authentication bypass issue read more about Hackers exploit critical auth bypass flaw in JobMonster WordPress ...

