Privilege Escalation Vulnerability in Nokri Job Board WordPress Theme
CVE-2025-1313

8.8HIGH

What is CVE-2025-1313?

The Nokri - Job Board WordPress Theme contains a vulnerability that allows authenticated users with Subscriber-level access or higher to escalate their privileges. This flaw is a result of inadequate user identity validation when updating personal information, such as email addresses. Attackers can exploit this weakness to alter arbitrary users' email addresses, including those of administrators. By doing so, they can initiate a password reset for the affected accounts, effectively gaining unauthorized access.

Affected Version(s)

Nokri – Job Board WordPress Theme * <= 1.6.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tonn
.
CVE-2025-1313 : Privilege Escalation Vulnerability in Nokri Job Board WordPress Theme