CVE-2025-9049
nicheMissing capability check in Nokri Job Board WordPress theme enables privilege escalation
CVE-2025-9049 is a broken access control flaw (CWE-862) in the Nokri – Job Board WordPress Theme: the 'nokri_account_member_permissions' function lacks a capability check in all versions up to and including 1.6.4. Any authenticated user with Subscriber-level access or above can invoke this function to create new Subscriber accounts that carry employer account member permissions. Those employer-permission members can in turn change the email address of any user on the site, including Administrators, allowing an attacker to hijack an admin account by changing its email and triggering a password reset. A successful attack therefore yields full administrative control of the affected WordPress site. No public proof-of-concept or known exploitation exists at this time, and the flaw is not listed in CISA's KEV.
What to do: Install a patched version of the Nokri theme as soon as one beyond 1.6.4 becomes available. Until then, limit or disable open subscriber registration, review recently created user accounts with employer member permissions, and audit whether any Administrator (or other) account email addresses have been unexpectedly changed. Any user account, even Subscriber-level, can trigger the flaw, so assume all authenticated users can reach it.
| Nokri – Job Board WordPress Theme | all versions up to and including 1.6.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add new Subscriber users with employer account member permissions, who in turn can escalate privileges by updating the email address of any user, including Administrator users.
- Ecosystems
- WordPress
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.