Executive brief
Jobmonster, a WordPress theme used for creating job board websites, is vulnerable to a security flaw that allows attackers to execute malicious scripts in a user's browser. By tricking a site visitor or administrator into clicking a specially crafted link, an attacker could steal login sessions, redirect users to fraudulent websites, or deface the site. This issue affects all versions up to 4.8.5 and has been resolved in version 4.8.5.1.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the NooTheme Jobmonster theme for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows an unauthenticated remote attacker to inject malicious scripts (HTML or JavaScript) into the application. Successful exploitation requires a victim to interact with a malicious link or visit a crafted page. Once executed, the script runs in the context of the victim's browser session, potentially allowing for session hijacking, unauthorized actions, or information disclosure. The vulnerability is present in versions up to and including 4.8.5 and is fixed in version 4.8.5.1.
Affected products
- NooTheme Jobmonster <= 4.8.5
Timeline
- 2026-05-18: disclosed: Reported by dutafi to Patchstack
- 2026-07-07: advisory: Patchstack published advisory
- 2026-07-13: advisory: NVD published CVE record