CVE-2025-53201: WordPress Jobmonster theme <= 4.7.8 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster allows Reflected XSS. This issue affects Jobmonster: from n/a through 4.7.8.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.7.8.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53201?
CVE-2025-53201 has been assigned a medium severity rating due to the potential for reflected XSS attacks.
How do I fix CVE-2025-53201?
To fix CVE-2025-53201, update NooTheme Jobmonster to version 4.7.9 or later.
What versions are affected by CVE-2025-53201?
CVE-2025-53201 affects NooTheme Jobmonster versions up to and including 4.7.8.
What is a reflected XSS vulnerability like CVE-2025-53201?
A reflected XSS vulnerability allows attackers to inject malicious scripts into web pages, which can lead to the theft of sensitive data.
Which products are impacted by CVE-2025-53201?
CVE-2025-53201 impacts NooTheme Jobmonster and WordPress Jobmonster themes.