Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

NooTheme — Vulnerabilities & Security Advisories 32

Browse all 32 CVE security advisories affecting NooTheme. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NooTheme operates as a developer of WordPress themes and plugins, primarily targeting e-commerce and business websites. Security audits have identified thirty-one distinct Common Vulnerabilities and Exposures (CVEs) associated with its software ecosystem, indicating a persistent pattern of insecure coding practices. The most prevalent vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from insufficient input validation and improper sanitization of user-supplied data. Additionally, several instances of broken access control and privilege escalation have been documented, allowing unauthorized users to manipulate administrative functions or access restricted resources. These flaws frequently arise from outdated dependencies and lack of rigorous security testing during the development lifecycle. While NooTheme has released patches for critical issues, the high volume of recorded CVEs suggests systemic weaknesses in their security architecture, posing significant risks to organizations relying on their products for web infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-57368 WordPress Jobmonster theme <= 4.8.5 - Reflected Cross Site Scripting (XSS) vulnerability — Jobmonster CWE-79 7.1 High 2026-07-13
CVE-2026-27049 WordPress Jobica Core plugin <= 1.4.2 - Account Takeover vulnerability — Jobica Core CWE-288 9.8 Critical 2026-03-25
CVE-2026-25340 WordPress Jobmonster theme < 4.8.4 - SQL Injection vulnerability — Jobmonster CWE-89 9.3 Critical 2026-03-25
CVE-2026-24981 WordPress Visionary Core plugin <= 1.4.9 - PHP Object Injection vulnerability — Visionary Core CWE-502 8.8 High 2026-03-25
CVE-2026-24980 WordPress Visionary Core plugin <= 1.4.9 - Reflected Cross Site Scripting (XSS) vulnerability — Visionary Core CWE-79 7.1 High 2026-03-25
CVE-2026-24976 WordPress Organici Library plugin <= 2.1.2 - PHP Object Injection vulnerability — Organici Library CWE-502 8.8 High 2026-03-25
CVE-2026-24979 WordPress Jobica Core plugin <= 1.4.1 - Reflected Cross Site Scripting (XSS) vulnerability — Jobica Core CWE-79 7.1 High 2026-03-25
CVE-2026-24978 WordPress Jobica Core plugin <= 1.4.1 - PHP Object Injection vulnerability — Jobica Core CWE-502 8.8 High 2026-03-25
CVE-2026-24977 WordPress Organici Library plugin <= 2.1.2 - SQL Injection vulnerability — Organici Library CWE-89 8.5 High 2026-03-25
CVE-2026-24975 WordPress Organici Library plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerability — Organici Library CWE-79 7.1 High 2026-03-25
CVE-2026-24974 WordPress CitiLights theme <= 3.7.1 - PHP Object Injection vulnerability — CitiLights CWE-502 8.8 High 2026-03-25
CVE-2026-24973 WordPress CitiLights theme <= 3.7.1 - Reflected Cross Site Scripting (XSS) vulnerability — CitiLights CWE-79 7.1 High 2026-03-25
CVE-2026-25367 WordPress CitiLights theme < 3.7.2 - Broken Access Control vulnerability — CitiLights CWE-862 5.3 Medium 2026-02-19
CVE-2025-67524 WordPress Jobmonster Elementor Addon plugin <= 1.1.4 - Local File Inclusion vulnerability — Jobmonster Elementor Addon CWE-98 7.5 High 2025-12-09
CVE-2025-67522 WordPress Jobmonster theme <= 4.8.2 - Local File Inclusion vulnerability — Jobmonster CWE-98 7.5 High 2025-12-09
CVE-2025-11985 Realty Portal <= 0.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update — Realty Portal CWE-862 8.8 High 2025-11-21
CVE-2025-54737 WordPress Jobmonster theme <= 4.7.8 - Cross Site Scripting (XSS) vulnerability — Jobmonster CWE-79 7.1 High 2025-11-06
CVE-2025-54718 WordPress Yogi - Health Beauty & Yoga theme <= 2.9.2 - Cross Site Scripting (XSS) vulnerability — Yogi - Health Beauty & Yoga CWE-79 7.1 High 2025-11-06
CVE-2025-54719 WordPress Yogi - Health Beauty & Yoga Theme <= 2.9.2 - Deserialization of untrusted data Vulnerability — Yogi - Health Beauty & Yoga CWE-502 8.8 High 2025-11-06
CVE-2025-53586 WordPress WeMusic Theme <= 1.9.1 - PHP Object Injection Vulnerability — WeMusic CWE-502 8.8 High 2025-11-06
CVE-2025-53585 WordPress WeMusic theme <= 1.9.1 - Cross Site Scripting (XSS) vulnerability — WeMusic CWE-79 7.1 High 2025-11-06
CVE-2025-54738 WordPress Jobmonster Theme <= 4.7.9 - Broken Authentication Vulnerability — Jobmonster CWE-288 9.8 Critical 2025-08-28
CVE-2025-57888 WordPress Jobmonster Theme <= 4.8.0 - Sensitive Data Exposure Vulnerability — Jobmonster CWE-497 5.3 Medium 2025-08-22
CVE-2025-57887 WordPress Jobmonster Theme <= 4.8.0 - Cross Site Scripting (XSS) Vulnerability — Jobmonster CWE-79 6.5 Medium 2025-08-22
CVE-2025-53201 WordPress Jobmonster theme <= 4.7.8 - Cross Site Scripting (XSS) vulnerability — Jobmonster CWE-79 7.1 High 2025-08-20
CVE-2025-6190 Realty Portal – Agent <= 0.3.9 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via rp_user_profile() Function — Realty Portal – Agent CWE-862 8.8 High 2025-07-23
CVE-2025-24779 WordPress Yogi theme < 2.9.3 - PHP Object Injection Vulnerability — Yogi CWE-502 8.8 High 2025-07-16
CVE-2025-3918 Job Listings 0.1 - 0.1.1 - Unauthenticated Privilege Escalation via register_action Function — Job Listings CWE-285 9.8 Critical 2025-05-03
CVE-2024-37928 WordPress Jobmonster theme <= 4.7.0 - Unauthenticated Arbitrary File Deletion vulnerability — Jobmonster CWE-22 8.6 High 2024-07-12
CVE-2024-37927 WordPress Jobmonster theme <= 4.7.5 - Unauthenticated Privilege Escalation vulnerability — Jobmonster CWE-266 9.8 Critical 2024-07-12

This page lists every published CVE security advisory associated with NooTheme. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.