← Terug naar overzicht

The Nokri Job Board WordPress Theme is vulnerable to Privilege Escalation via Account Takeover in all versions up to and including 1.6.6. The vulnerability exists in the nokri_reset_password() function due to insufficient reset token validation. Attackers can supply an empty reset token that matches empty or unset sb_password_forget_token user meta values. This allows unauthenticated attackers to reset the password of any user, including administrators. Successful exploitation grants full account access without any prior authentication. The vulnerability is classified as critical given that it enables complete administrative account takeover. Users of the Nokri theme should update to a patched version immediately to mitigate the risk.

Affected products

  • Nokri - Job Board WordPress Theme <= 1.6.6

Related CVE's

  • CVE-2026-18550

Categories

  • Identity & Access
  • Web Technologies
  • Zero-Day Vulnerabilities