CVE-2026-18550
nicheUnauthenticated Account Takeover via Flawed Password Reset in Nokri Job Board WordPress Theme
The Nokri Job Board WordPress theme fails to properly validate password reset tokens in its nokri_reset_password() function, allowing an attacker-supplied empty token to match a user's empty or unset sb_password_forget_token meta value. Because reset tokens are only set after a user requests a password reset, most users have this field unset, so an unauthenticated attacker can trigger a password reset for any user, including administrators. By then logging in with the password they set, the attacker gains full control of the targeted account, and on an administrator account this typically leads to complete site takeover. All versions up to and including 1.6.6 are affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts near-term exploitation probability at roughly 0.3%, so exploitation is not known to be occurring yet.
What to do: Update the Nokri theme to the first release after version 1.6.6 as soon as a patched version is available. Until patched, watch administrator and user accounts for unexpected password resets or logins, and consider restricting the theme's password-reset endpoint via a firewall rule. If compromise is suspected, rotate all credentials and review recently changed accounts.
| Nokri - Job Board WordPress Theme (WordPress) | all versions up to and including 1.6.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` function, which allows empty attacker-supplied reset tokens to match empty or unset `sb_password_forget_token` user meta values. This makes it possible for unauthenticated attackers to reset the password of any user, including administrators, and gain access to their account.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.