theme

Noo Jobmonster Vulnerabilities

24 known security issues reported for the Noo Jobmonster WordPress theme. Most recent disclosed Jul 7, 2026.

4 critical 2 high 7 medium

Running Noo Jobmonster on your site? Check whether your installed version is affected.

Scan your site free

Noo JobMonster <= 4.8.5 - Reflected Cross-Site Scripting

medium

The Noo JobMonster theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.8.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...

CVSS:
6.1
Affected:
up to 4.8.5
Fixed in:
4.8.5.1
Disclosed:
Jul 7, 2026

CVE-2026-57368 on NVD →

Noo JobMonster < 4.8.4 - Unauthenticated SQL Injection

high

The Noo JobMonster theme for WordPress is vulnerable to SQL Injection in versions up to 4.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already exist...

CVSS:
7.5
Affected:
up to 4.8.4
Fixed in:
4.8.4
Disclosed:
Mar 23, 2026

CVE-2026-25340 on NVD →

Jobmonster <= 4.8.2 - Authenticated (Contributor+) Local File Inclusion

high

The Jobmonster theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.8.2. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...

CVSS:
7.5
Affected:
up to 4.8.2
Fixed in:
4.8.3
Disclosed:
Dec 12, 2025

CVE-2025-67522 on NVD →

Jobmonster [noo-jobmonster] <= 4.8.2 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NooTheme Jobmonster noo-jobmonster allows PHP Local File Inclusion.This issue affects Jobmonster: from n/a through <= 4.8.2.

Affected:
up to 4.8.2
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67522 on NVD →

Jobmonster [noo-jobmonster] <= 4.7.8 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.7.8.

Affected:
up to 4.7.8
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-54737 on NVD →

Jobmonster - Job Board WordPress Theme <= 4.8.1 - Authentication Bypass

critical

The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authenticating them This makes it possible for unauthenticated attackers to bypass standard...

CVSS:
9.8
Affected:
up to 4.8.1
Fixed in:
4.8.2
Disclosed:
Oct 30, 2025

CVE-2025-5397 on NVD →

Jobmonster <= 4.7.8 - Reflected Cross-Site Scripting

medium

The Jobmonster theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick...

CVSS:
6.1
Affected:
up to 4.7.8
Fixed in:
4.7.9
Disclosed:
Aug 31, 2025

CVE-2025-54737 on NVD →

Jobmonster [noo-jobmonster] < 4.8.0

unknown

[en] Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster allows Authentication Abuse. This issue affects Jobmonster: from n/a through 4.7.9.

Affected:
up to 4.8.0
Fixed in:
4.8.0
Disclosed:
Aug 28, 2025

CVE-2025-54738 on NVD →

Jobmonster <= 4.8.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Jobmonster theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 4.8.0
Fixed in:
4.8.1
Disclosed:
Aug 22, 2025

CVE-2025-57887 on NVD →

Jobmonster <= 4.8.0 - Unauthenticated Sensitive Information Disclosure

medium

The Noo JobMonster theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.8.0. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 4.8.0
Fixed in:
4.8.1
Disclosed:
Aug 22, 2025

CVE-2025-57888 on NVD →

Jobmonster [noo-jobmonster] < 4.8.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster allows Stored XSS. This issue affects Jobmonster: from n/a through 4.8.0.

Affected:
up to 4.8.1
Fixed in:
4.8.1
Disclosed:
Aug 22, 2025

CVE-2025-57887 on NVD →

Jobmonster [noo-jobmonster] < 4.8.1

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NooTheme Jobmonster allows Retrieve Embedded Sensitive Data. This issue affects Jobmonster: from n/a through 4.8.0.

Affected:
up to 4.8.1
Fixed in:
4.8.1
Disclosed:
Aug 22, 2025

CVE-2025-57888 on NVD →

Jobmonster <= 4.7.9 - Authentication Bypass

critical

The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.7.9.This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.

CVSS:
9.8
Affected:
up to 4.7.9
Fixed in:
4.8.0
Disclosed:
Aug 21, 2025

CVE-2025-54738 on NVD →

Jobmonster [noo-jobmonster] < 4.7.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster allows Reflected XSS. This issue affects Jobmonster: from n/a through 4.7.8.

Affected:
up to 4.7.9
Fixed in:
4.7.9
Disclosed:
Aug 20, 2025

CVE-2025-53201 on NVD →

Jobmonster <= 4.7.8 - Reflected Cross-Site Scripting

medium

The Noo JobMonster theme for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.7.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successful...

CVSS:
6.1
Affected:
up to 4.7.8
Fixed in:
4.7.9
Disclosed:
Jul 23, 2025

CVE-2025-53201 on NVD →

Jobmonster [noo-jobmonster] <= 4.7.0 (unfixed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allows File Manipulation.This issue affects Jobmonster: from n/a through 4.7.0.

Affected:
up to 4.7.0
Fix:
No patched version reported
Disclosed:
Jul 12, 2024

CVE-2024-37928 on NVD →

Jobmonster [noo-jobmonster] <= 4.7.0 (unfixed)

unknown

[en] Improper Privilege Management vulnerability in NooTheme Jobmonster allows Privilege Escalation.This issue affects Jobmonster: from n/a through 4.7.0.

Affected:
up to 4.7.0
Fix:
No patched version reported
Disclosed:
Jul 12, 2024

CVE-2024-37927 on NVD →

Jobmonster <= 4.7.5 - Unauthenticated Privilege Escalation

critical

The Noo JobMonster theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7.5. This makes it possible for unauthenticated attackers to gain higher privileged access to a vulnerable site.

CVSS:
9.8
Affected:
up to 4.7.5
Fixed in:
4.7.6
Disclosed:
Jul 9, 2024

CVE-2024-37927 on NVD →

Jobmonster < 4.7.5 - Unauthenticated Arbitrary File Deletion

critical

The Noo JobMonster theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and not including, 4.7.5. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execu...

CVSS:
9.1
Affected:
up to 4.7.5
Fixed in:
4.7.5
Disclosed:
Jul 9, 2024

CVE-2024-37928 on NVD →

Jobmonster [noo-jobmonster] < 4.6.6.1

unknown

[en] The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file. This could expose personal data such as people's resumes. Although Directory Listing can be prevented by securely configuring the web server, vendors...

Affected:
up to 4.6.6.1
Fixed in:
4.6.6.1
Disclosed:
Apr 4, 2022

CVE-2022-1166 on NVD →

Jobmonster [noo-jobmonster] < 4.6.6.1

unknown

[en] In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

Affected:
up to 4.6.6.1
Fixed in:
4.6.6.1
Disclosed:
Apr 4, 2022

CVE-2022-1170 on NVD →

Jobmonster [noo-jobmonster] < 4.6.6.1

unknown

Directory Listing in Upload Folder vulnerability found by Daniel Ruf in WordPress JobMonster premium theme (versions <= 4.6.6).

Affected:
up to 4.6.6.1
Fixed in:
4.6.6.1
Disclosed:
Sep 21, 2020

Noo JobMonster <= 4.6.6 - Sensitive Information Disclosure via Directory Listing

medium

The Noo JobMonster theme is vulnerable to Sensitive Information Disclosure via Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not include a default PHP file, or .htaccess file in versions up to, and including 4.6.6. This could expose personal data such as people's resumes. Although Directory...

CVSS:
5.3
Affected:
up to 4.6.6
Fixed in:
4.6.6.1
Disclosed:
Sep 11, 2020

CVE-2022-1166 on NVD →

Noo JobMonster < 4.5.2.9 - Reflected Cross-Site Scripting

medium

In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search form is provided through unsanitized GET requests.

CVSS:
6.1
Affected:
up to 4.5.2.9
Fixed in:
4.5.2.9
Disclosed:
Oct 24, 2019

CVE-2022-1170 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database