CVE-2025-5397Critical· 9.8▾ MidnightThe Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authentic…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8.1. This is due to the check_login() function not properly verifying a user's identity prior to successfully authenticating them This makes it possible for unauthenticated attackers to bypass standard authentication and access administrative user accounts. Please note social login needs to be enabled in order for a site to be impacted by this vulnerability.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14714Medium· 6.5An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executi…
CVE-2026-107194Critical· 9.2Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe
CVE-2026-19572Critical· 9.3A security vulnerability has been identified in FlexNet Publisher lmadmin
CVE-2026-39769High· 7.5Unauthenticated Broken Authentication in Graphina <= 3.1.12 versions.
CVE-2026-39793High· 8.8Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
CVE-2026-100518Medium· 5.3Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.