CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

JobMonster WordPress Theme Authentication Bypass Exploits

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Threat actors are actively exploiting a critical authentication bypass vulnerability (CVE-2025-5397) in the JobMonster WordPress theme. This flaw allows unauthenticated attackers to hijack administrator accounts if social login is enabled. The vulnerability affects all versions up to 4.8.1 and has been patched in version 4.8.2. The JobMonster theme is used by job listing sites and recruitment portals, with over 5,500 sales on Envato. The flaw is due to improper verification of user identity in the check_login() function, enabling attackers to bypass standard authentication. To mitigate the risk, users are advised to update to the latest version, disable social login, enable two-factor authentication, and monitor access logs for suspicious activity.

Timeline

  1. 04.11.2025 09:49 1 articles · 6d ago

    Critical Authentication Bypass Vulnerability in JobMonster Theme Exploited

    Threat actors are actively exploiting a critical authentication bypass vulnerability (CVE-2025-5397) in the JobMonster WordPress theme. This flaw allows unauthenticated attackers to hijack administrator accounts if social login is enabled. The vulnerability affects all versions up to 4.8.1 and has been patched in version 4.8.2. The flaw is due to improper verification of user identity in the check_login() function, enabling attackers to bypass standard authentication. Users are advised to update to the latest version, disable social login, enable two-factor authentication, and monitor access logs for suspicious activity.

    Show sources

Information Snippets