Impact
A flaw exists in NooTheme Jobmonster versions up to and including 4.8.0 that allows an attacker to retrieve embedded sensitive system data. The vulnerability is classified as a sensitive data exposure, meaning that private information stored within the theme or WordPress environment can be accessed by an unauthorized user. The implications are primarily confidentiality‑related, with potential disclosure of configuration settings, user credentials, or other sensitive details.
Affected Systems
WordPress sites using NooTheme Jobmonster theme through version 4.8.0 are impacted. No specific sub‑versions are listed beyond the upper bound; all releases before and up to 4.8.0 lack the mitigation needed to prevent data leakage.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the medium severity range, and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the near term. The vulnerability is not listed in CISA's KEV catalog. While the description does not explicitly state the attack vector, it is inferred that an unauthenticated web user can trigger the data retrieval through the theme’s publicly accessible interfaces. Once the flaw is exploited, an attacker gains direct access to sensitive system information without additional access privileges.
OpenCVE Enrichment
EUVD