CVE-2025-54737: WordPress Jobmonster theme <= 4.7.8 - Cross Site Scripting (XSS) vulnerability
Published Nov 6, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.7.8.
Affected Software
2 affected components
NooTheme Jobmonster<=4.7.8
WordPress Jobmonster<=4.7.8
Event History
Nov 6, 2025
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-54737?
CVE-2025-54737 has a medium severity rating due to the potential for reflected XSS attacks.
2
How do I fix CVE-2025-54737?
To fix CVE-2025-54737, update NooTheme Jobmonster theme to the latest version beyond 4.7.8.
3
What systems are affected by CVE-2025-54737?
CVE-2025-54737 affects NooTheme Jobmonster versions up to and including 4.7.8.
4
What is reflected XSS in the context of CVE-2025-54737?
Reflected XSS in CVE-2025-54737 allows attackers to inject malicious scripts that execute immediately in the user's browser.
5
Can CVE-2025-54737 affect my website's reputation?
Yes, exploitation of CVE-2025-54737 can harm your website's reputation and compromise user trust due to potential data leaks.