
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-5397 is a critical authentication bypass vulnerability in the Noo JobMonster theme for WordPress, affecting all versions up to and including 4.8.1. The flaw resides in the check_login() function, which fails to properly verify a user's identity before authenticating them, enabling unauthenticated attackers to gain access to administrative accounts. The vulnerability was published on October 31, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) and is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). Exploitation requires that the social login feature be enabled on the affected WordPress site (Wordfence, ENISA EUVD).
The root cause is CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the check_login() function in the Noo JobMonster theme does not adequately verify a user's identity when processing social login requests, allowing an attacker to authenticate as any user — including administrators — without valid credentials. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity, making it trivially exploitable remotely. The critical precondition is that the WordPress site must have the social login feature enabled; sites with social login disabled are not affected. No public proof-of-concept code has been confirmed, but active exploitation in the wild has been reported (Wordfence, SecurityOnline).
Successful exploitation grants an unauthenticated attacker full administrative access to the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. Attackers can steal sensitive data (user credentials, personal information, payment data), modify or deface site content, install malicious plugins or backdoors, and leverage the compromised site for further attacks such as phishing campaigns or malware distribution. The scope of impact is limited to the affected WordPress instance, but lateral movement within the hosting environment is possible if the attacker escalates further (Wordfence, BleepingComputer).
CVE-2025-5397 has been confirmed as actively exploited in the wild, with multiple sources reporting real-world attacks against WordPress sites running the vulnerable JobMonster theme (BleepingComputer, SecurityOnline). No public proof-of-concept exploit code has been confirmed, though exploitation has been reported by multiple threat intelligence sources. The EPSS score is approximately 0.0022 (0.22%), though this may not fully reflect the observed in-the-wild activity. No specific threat actor attribution has been published. The vulnerability does not appear in the CISA KEV catalog as of the available data, though CISA did add related WordPress-targeting flaws around the same period (The Hacker News).
inurl:wp-content/themes/jobmonster). Confirm that social login is enabled on the target site by visiting the login page and checking for social login buttons.check_login() function. Manipulate the identity parameters (e.g., social provider token or user identifier fields) to reference a target administrative account without providing valid authentication credentials.check_login(), the server authenticates the attacker as the targeted user (e.g., the site administrator) without validating the supplied identity./wp-login.php, theme-specific AJAX handlers) from unexpected IP addresses or with anomalous parameters; outbound connections from the web server to unknown external hosts.wp-content/uploads/ or theme directories; modifications to wp-config.php or .htaccess.curl, wget, bash) indicating post-exploitation activity (BleepingComputer, Wordfence).The primary remediation is to update the Noo JobMonster WordPress theme to a version beyond 4.8.1, which contains the fix for the check_login() authentication bypass (Wordfence, ENISA EUVD). As an immediate workaround, disable the social login feature in the theme settings if it is not critically required, as this eliminates the attack surface entirely. Additionally, site administrators should audit all administrator accounts for unauthorized access, reset all user passwords, review recently installed plugins and file changes, and consider enabling two-factor authentication for admin accounts.
BleepingComputer reported active exploitation of the vulnerability, drawing significant attention from the security community (BleepingComputer). Wordfence, which discovered and assigned the CVE, published a detailed threat intelligence entry and included it in their weekly WordPress vulnerability report (Wordfence Blog). SecurityOnline highlighted the critical nature of the flaw and its active exploitation status, and the vulnerability was discussed across social media platforms including LinkedIn, Bluesky, and Mastodon. SC World and TechZine also covered the story, reflecting broad industry concern about the risk to WordPress-based job board sites (SC World).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."