top of page
perceptive_background_267k.jpg

The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This…

Published:

1 September 2026 at 00:00:00

Alert date:

1 September 2026 at 15:04:21

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Zero-Day Vulnerabilities

The Nokri Job Board WordPress Theme is vulnerable to Privilege Escalation via Account Takeover in all versions up to and including 1.6.6. The vulnerability exists in the nokri_reset_password() function due to insufficient reset token validation. Attackers can supply an empty reset token that matches empty or unset sb_password_forget_token user meta values. This allows unauthenticated attackers to reset the password of any user, including administrators. Successful exploitation grants full account access without any prior authentication. The vulnerability is classified as critical given that it enables complete administrative account takeover. Users of the Nokri theme should update to a patched version immediately to mitigate the risk.

Technical details

Mitigation steps:

Affected products:

Nokri - Job Board WordPress Theme <= 1.6.6

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page