CVE-2026-57368: WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vulnerability
Published Jul 13, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Reflected XSS.This issue affects Jobmonster: from n/a through <= 4.8.5.
Affected Software
1 affected component
NooTheme Jobmonster<=4.8.5
Event History
Jul 13, 2026
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57368?
CVE-2026-57368 has a high severity rating of 7.1.
2
How do I fix CVE-2026-57368?
To fix CVE-2026-57368, update the NooTheme Jobmonster theme to the latest version beyond 4.8.5.
3
What type of vulnerability is CVE-2026-57368?
CVE-2026-57368 is a Reflected Cross Site Scripting (XSS) vulnerability.
4
Which versions of Jobmonster are affected by CVE-2026-57368?
CVE-2026-57368 affects Jobmonster versions from n/a through 4.8.5.
5
What impact can CVE-2026-57368 have?
CVE-2026-57368 can lead to unauthorized execution of scripts in the user's browser, potentially compromising user data.