CVE-2026-18550 affects the Nokri Job Board WordPress Theme in all versions up to and including 1.6.6. The vulnerability exists in the nokri_reset_password() function due to insufficient reset token validation. Attackers can supply an empty reset token that matches empty or unset sb_password_forget_token user meta values. This allows unauthenticated attackers to reset passwords for any user account, including administrators. Successful exploitation leads to full account takeover and privilege escalation. No authentication is required to exploit this vulnerability. The flaw is classified as a Privilege Escalation via Account Takeover. Users are advised to update beyond version 1.6.6 to remediate the issue.