CVE-2025-5397
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-5397 is a critical authentication bypass vulnerability in the Noo JobMonster theme for WordPress, affecting all versions up to and including 4.8.1. The flaw resides in the check_login() function, which fails to properly verify a user's identity before authenticating them, enabling unauthenticated attackers to gain access to administrative accounts. The vulnerability was published on October 31, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) and is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). Exploitation requires that the social login feature be enabled on the affected WordPress site (Wordfence, ENISA EUVD).

Technical details

The root cause is CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the check_login() function in the Noo JobMonster theme does not adequately verify a user's identity when processing social login requests, allowing an attacker to authenticate as any user — including administrators — without valid credentials. The attack vector is network-based, requires no privileges or user interaction, and has low attack complexity, making it trivially exploitable remotely. The critical precondition is that the WordPress site must have the social login feature enabled; sites with social login disabled are not affected. No public proof-of-concept code has been confirmed, but active exploitation in the wild has been reported (Wordfence, SecurityOnline).

Impact

Successful exploitation grants an unauthenticated attacker full administrative access to the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. Attackers can steal sensitive data (user credentials, personal information, payment data), modify or deface site content, install malicious plugins or backdoors, and leverage the compromised site for further attacks such as phishing campaigns or malware distribution. The scope of impact is limited to the affected WordPress instance, but lateral movement within the hosting environment is possible if the attacker escalates further (Wordfence, BleepingComputer).

Exploitability

CVE-2025-5397 has been confirmed as actively exploited in the wild, with multiple sources reporting real-world attacks against WordPress sites running the vulnerable JobMonster theme (BleepingComputer, SecurityOnline). No public proof-of-concept exploit code has been confirmed, though exploitation has been reported by multiple threat intelligence sources. The EPSS score is approximately 0.0022 (0.22%), though this may not fully reflect the observed in-the-wild activity. No specific threat actor attribution has been published. The vulnerability does not appear in the CISA KEV catalog as of the available data, though CISA did add related WordPress-targeting flaws around the same period (The Hacker News).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Noo JobMonster theme (versions ≤ 4.8.1) via passive scanning tools (e.g., WPScan, Shodan, or Google dorks such as inurl:wp-content/themes/jobmonster). Confirm that social login is enabled on the target site by visiting the login page and checking for social login buttons.
  2. Craft malicious social login request: Prepare an HTTP request targeting the social login endpoint handled by the check_login() function. Manipulate the identity parameters (e.g., social provider token or user identifier fields) to reference a target administrative account without providing valid authentication credentials.
  3. Submit the bypass request: Send the crafted request to the WordPress site's social login handler. Due to the lack of proper identity verification in check_login(), the server authenticates the attacker as the targeted user (e.g., the site administrator) without validating the supplied identity.
  4. Gain administrative access: Upon successful bypass, the attacker receives a valid WordPress session cookie for the administrative account, granting full access to the WordPress admin dashboard.
  5. Post-exploitation: Install a malicious plugin or web shell for persistent backdoor access, exfiltrate user data from the database, modify site content, or use the site as a platform for further attacks (BleepingComputer, Wordfence).

Indicators of compromise

  • Network: Unusual or repeated HTTP POST/GET requests to WordPress social login endpoints (e.g., /wp-login.php, theme-specific AJAX handlers) from unexpected IP addresses or with anomalous parameters; outbound connections from the web server to unknown external hosts.
  • Logs: WordPress access logs showing successful authentication events for administrator accounts from unfamiliar IP addresses or at unusual times; repeated requests to social login handler URLs with missing or malformed OAuth tokens.
  • File System: Presence of newly installed or modified plugins not authorized by site administrators; unexpected PHP files (web shells) in the wp-content/uploads/ or theme directories; modifications to wp-config.php or .htaccess.
  • WordPress Admin: New administrator accounts created without authorization; changes to site settings, installed plugins, or theme files; unexpected scheduled tasks (cron jobs) added via WordPress admin.
  • Process: Unusual child processes spawned by the web server process (e.g., curl, wget, bash) indicating post-exploitation activity (BleepingComputer, Wordfence).

Mitigation and workarounds

The primary remediation is to update the Noo JobMonster WordPress theme to a version beyond 4.8.1, which contains the fix for the check_login() authentication bypass (Wordfence, ENISA EUVD). As an immediate workaround, disable the social login feature in the theme settings if it is not critically required, as this eliminates the attack surface entirely. Additionally, site administrators should audit all administrator accounts for unauthorized access, reset all user passwords, review recently installed plugins and file changes, and consider enabling two-factor authentication for admin accounts.

Community reactions

BleepingComputer reported active exploitation of the vulnerability, drawing significant attention from the security community (BleepingComputer). Wordfence, which discovered and assigned the CVE, published a detailed threat intelligence entry and included it in their weekly WordPress vulnerability report (Wordfence Blog). SecurityOnline highlighted the critical nature of the flaw and its active exploitation status, and the vulnerability was discussed across social media platforms including LinkedIn, Bluesky, and Mastodon. SC World and TechZine also covered the story, reflecting broad industry concern about the risk to WordPress-based job board sites (SC World).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18039NONEN/A
  • essential-addons-for-elementor-lite
NoYesAug 14, 2026
CVE-2026-16810NONEN/A
  • bit-form
NoYesAug 14, 2026
CVE-2026-16739NONEN/A
  • epeken-all-kurir
NoNoAug 14, 2026
CVE-2026-15205NONEN/A
  • paymob-for-woocommerce
NoYesAug 14, 2026
CVE-2026-14290NONEN/A
  • embed-google-photos-album-easily
NoNoAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management