ZeroHour

CVE-2025-9049

niche

Missing capability check in Nokri Job Board WordPress theme enables privilege escalation

CVSS 3.1
8.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2025-9049 is a broken access control flaw (CWE-862) in the Nokri – Job Board WordPress Theme: the 'nokri_account_member_permissions' function lacks a capability check in all versions up to and including 1.6.4. Any authenticated user with Subscriber-level access or above can invoke this function to create new Subscriber accounts that carry employer account member permissions. Those employer-permission members can in turn change the email address of any user on the site, including Administrators, allowing an attacker to hijack an admin account by changing its email and triggering a password reset. A successful attack therefore yields full administrative control of the affected WordPress site. No public proof-of-concept or known exploitation exists at this time, and the flaw is not listed in CISA's KEV.

What to do: Install a patched version of the Nokri theme as soon as one beyond 1.6.4 becomes available. Until then, limit or disable open subscriber registration, review recently created user accounts with employer member permissions, and audit whether any Administrator (or other) account email addresses have been unexpectedly changed. Any user account, even Subscriber-level, can trigger the flaw, so assume all authenticated users can reach it.

Affected
Nokri – Job Board WordPress Themeall versions up to and including 1.6.4
Estimated exposure
nichelikely low thousands of sites — Nokri is a premium commercial WordPress theme sold through ThemeForest in the job-board niche, where such themes are typically deployed on hundreds to a few thousand sites; exact install counts are not publicly published.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add new Subscriber users with employer account member permissions, who in turn can escalate privileges by updating the email address of any user, including Administrator users.

Ecosystems
WordPress
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.