Impact
The vulnerability is an authentication bypass that allows an attacker to authenticate using an alternate path or channel, effectively abusing the authentication mechanism. Exploitation would give the attacker unauthorized access to any protected area of the WordPress site where the Jobmonster theme is active, potentially including administrative functions and sensitive data. The weakness is classified as CWE‑288, an authentication and authorization failure.
Affected Systems
All installations of the NooTheme Jobmonster WordPress theme released up to and including version 4.7.9 are affected. The vulnerability applies to every version from an unspecified earliest release through 4.7.9.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. However, the EPSS score is reported as below 1 %, implying a very low chance of exploitation in the wild at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves remote exploitation via the WordPress web interface, where an attacker can trigger the alternate authentication path without needing valid credentials.
OpenCVE Enrichment
EUVD