Noo JobMonster <= 4.8.5 - Reflected Cross-Site Scripting
medium
The Noo JobMonster theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 4.8.5
- Fixed in:
- 4.8.5.1
- Disclosed:
- Jul 7, 2026
CVE-2026-57368 on NVD →
Noo JobMonster < 4.8.4 - Unauthenticated SQL Injection
high
The Noo JobMonster theme for WordPress is vulnerable to SQL Injection in versions up to 4.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already exist...
- CVSS:
- 7.5
- Affected:
- up to 4.8.4
- Fixed in:
- 4.8.4
- Disclosed:
- Mar 23, 2026
CVE-2026-25340 on NVD →
Jobmonster <= 4.8.2 - Authenticated (Contributor+) Local File Inclusion
high
The Jobmonster theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.8.2. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 7.5
- Affected:
- up to 4.8.2
- Fixed in:
- 4.8.3
- Disclosed:
- Dec 12, 2025
CVE-2025-67522 on NVD →
Jobmonster [noo-jobmonster] <= 4.8.2 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NooTheme Jobmonster noo-jobmonster allows PHP Local File Inclusion.This issue affects Jobmonster: from n/a through <= 4.8.2.
- Affected:
- up to 4.8.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67522 on NVD →
Jobmonster [noo-jobmonster] <= 4.7.8 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.7.8.
- Affected:
- up to 4.7.8
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-54737 on NVD →
Jobmonster - Job Board WordPress Theme <= 4.8.1 - Authentication Bypass
critical
The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authenticating them This makes it possible for unauthenticated attackers to bypass standard...
- CVSS:
- 9.8
- Affected:
- up to 4.8.1
- Fixed in:
- 4.8.2
- Disclosed:
- Oct 30, 2025
CVE-2025-5397 on NVD →
Jobmonster <= 4.7.8 - Reflected Cross-Site Scripting
medium
The Jobmonster theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...
- CVSS:
- 6.1
- Affected:
- up to 4.7.8
- Fixed in:
- 4.7.9
- Disclosed:
- Aug 31, 2025
CVE-2025-54737 on NVD →
Jobmonster [noo-jobmonster] < 4.8.0
unknown
[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster allows Authentication Abuse. This issue affects Jobmonster: from n/a through 4.7.9.
- Affected:
- up to 4.8.0
- Fixed in:
- 4.8.0
- Disclosed:
- Aug 28, 2025
CVE-2025-54738 on NVD →
Jobmonster <= 4.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Jobmonster theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 4.8.0
- Fixed in:
- 4.8.1
- Disclosed:
- Aug 22, 2025
CVE-2025-57887 on NVD →
Jobmonster <= 4.8.0 - Unauthenticated Sensitive Information Disclosure
medium
The Noo JobMonster theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.8.0
- Fixed in:
- 4.8.1
- Disclosed:
- Aug 22, 2025
CVE-2025-57888 on NVD →
Jobmonster [noo-jobmonster] < 4.8.1
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster allows Stored XSS. This issue affects Jobmonster: from n/a through 4.8.0.
- Affected:
- up to 4.8.1
- Fixed in:
- 4.8.1
- Disclosed:
- Aug 22, 2025
CVE-2025-57887 on NVD →
Jobmonster [noo-jobmonster] < 4.8.1
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NooTheme Jobmonster allows Retrieve Embedded Sensitive Data. This issue affects Jobmonster: from n/a through 4.8.0.
- Affected:
- up to 4.8.1
- Fixed in:
- 4.8.1
- Disclosed:
- Aug 22, 2025
CVE-2025-57888 on NVD →
Jobmonster <= 4.7.9 - Authentication Bypass
critical
The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.7.9.This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.
- CVSS:
- 9.8
- Affected:
- up to 4.7.9
- Fixed in:
- 4.8.0
- Disclosed:
- Aug 21, 2025
CVE-2025-54738 on NVD →
Jobmonster [noo-jobmonster] < 4.7.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster allows Reflected XSS. This issue affects Jobmonster: from n/a through 4.7.8.
- Affected:
- up to 4.7.9
- Fixed in:
- 4.7.9
- Disclosed:
- Aug 20, 2025
CVE-2025-53201 on NVD →
Jobmonster <= 4.7.8 - Reflected Cross-Site Scripting
medium
The Noo JobMonster theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successful...
- CVSS:
- 6.1
- Affected:
- up to 4.7.8
- Fixed in:
- 4.7.9
- Disclosed:
- Jul 23, 2025
CVE-2025-53201 on NVD →
Jobmonster [noo-jobmonster] <= 4.7.0 (unfixed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allows File Manipulation.This issue affects Jobmonster: from n/a through 4.7.0.
- Affected:
- up to 4.7.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 12, 2024
CVE-2024-37928 on NVD →
Jobmonster [noo-jobmonster] <= 4.7.0 (unfixed)
unknown
[en] Improper Privilege Management vulnerability in NooTheme Jobmonster allows Privilege Escalation.This issue affects Jobmonster: from n/a through 4.7.0.
- Affected:
- up to 4.7.0
- Fix:
- No patched version reported
- Disclosed:
- Jul 12, 2024
CVE-2024-37927 on NVD →
Jobmonster <= 4.7.5 - Unauthenticated Privilege Escalation
critical
The Noo JobMonster theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7.5. This makes it possible for unauthenticated attackers to gain higher privileged access to a vulnerable site.
- CVSS:
- 9.8
- Affected:
- up to 4.7.5
- Fixed in:
- 4.7.6
- Disclosed:
- Jul 9, 2024
CVE-2024-37927 on NVD →
Jobmonster < 4.7.5 - Unauthenticated Arbitrary File Deletion
critical
The Noo JobMonster theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and not including, 4.7.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execu...
- CVSS:
- 9.1
- Affected:
- up to 4.7.5
- Fixed in:
- 4.7.5
- Disclosed:
- Jul 9, 2024
CVE-2024-37928 on NVD →
Jobmonster [noo-jobmonster] < 4.6.6.1
unknown
[en] The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors...
- Affected:
- up to 4.6.6.1
- Fixed in:
- 4.6.6.1
- Disclosed:
- Apr 4, 2022
CVE-2022-1166 on NVD →
Jobmonster [noo-jobmonster] < 4.6.6.1
unknown
[en] In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
- Affected:
- up to 4.6.6.1
- Fixed in:
- 4.6.6.1
- Disclosed:
- Apr 4, 2022
CVE-2022-1170 on NVD →
Jobmonster [noo-jobmonster] < 4.6.6.1
unknown
Directory Listing in Upload Folder vulnerability found by Daniel Ruf in WordPress JobMonster premium theme (versions <= 4.6.6).
- Affected:
- up to 4.6.6.1
- Fixed in:
- 4.6.6.1
- Disclosed:
- Sep 21, 2020
Noo JobMonster <= 4.6.6 - Sensitive Information Disclosure via Directory Listing
medium
The Noo JobMonster theme is vulnerable to Sensitive Information Disclosure via Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file in versions up to, and including 4.6.6. This could expose personal data such as people's resumes. Although Directory...
- CVSS:
- 5.3
- Affected:
- up to 4.6.6
- Fixed in:
- 4.6.6.1
- Disclosed:
- Sep 11, 2020
CVE-2022-1166 on NVD →
Noo JobMonster < 4.5.2.9 - Reflected Cross-Site Scripting
medium
In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.
- CVSS:
- 6.1
- Affected:
- up to 4.5.2.9
- Fixed in:
- 4.5.2.9
- Disclosed:
- Oct 24, 2019
CVE-2022-1170 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database