


Perceptive Security
SOC/SIEM Consultancy

The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This…
Published:
1 September 2026 at 00:00:00
Alert date:
1 September 2026 at 15:04:21
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
The Nokri Job Board WordPress Theme is vulnerable to Privilege Escalation via Account Takeover in all versions up to and including 1.6.6. The vulnerability exists in the nokri_reset_password() function due to insufficient reset token validation. Attackers can supply an empty reset token that matches empty or unset sb_password_forget_token user meta values. This allows unauthenticated attackers to reset the password of any user, including administrators. Successful exploitation grants full account access without any prior authentication. The vulnerability is classified as critical given that it enables complete administrative account takeover. Users of the Nokri theme should update to a patched version immediately to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
Nokri - Job Board WordPress Theme <= 1.6.6
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18550
https://nokriwp.com/
https://themeforest.net/item/nokri-job-board-wordpress-theme/22677241
https://www.wordfence.com/threat-intel/vulnerabilities/id/b03b7ea8-6485-495d-b815-2b7b882a75a2?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
