CVE-2026-18550
Received Received - Intake

Privilege Escalation via Account Takeover in Nokri Job Board WordPress Theme

Vulnerability report for CVE-2026-18550, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Wordfence

Description

The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` function, which allows empty attacker-supplied reset tokens to match empty or unset `sb_password_forget_token` user meta values. This makes it possible for unauthenticated attackers to reset the password of any user, including administrators, and gain access to their account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
nokri nokri_job_board_wordpress_theme to 1.6.6 (inc)
nokri nokri to 1.6.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated attackers to reset passwords of any user, including administrators, by exploiting weak token validation in the Nokri WordPress theme. The flaw exists in the password reset function due to insufficient checks on reset tokens.

Detection Guidance

Check WordPress sites using the Nokri theme version 1.6.6 or earlier for unauthorized password reset attempts or admin account changes. Inspect user meta values for 'sb_password_forget_token' and review access logs for suspicious reset token submissions.

Impact Analysis

Attackers could gain full control of user accounts, steal sensitive data, or perform unauthorized actions. If you use this theme, your WordPress site could be compromised, leading to data breaches or malware distribution.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations may face fines or legal consequences if exploited.

Mitigation Strategies

Update the Nokri theme to the latest version beyond 1.6.6 immediately. If an update is unavailable, disable the theme or implement a firewall rule to block requests targeting the nokri_reset_password() function. Reset all user passwords, especially admin accounts, and review user accounts for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18550. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart