Privilege Escalation Vulnerability in Nokri Job Board WordPress Theme
CVE-2025-1313
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 July 2025
What is CVE-2025-1313?
The Nokri - Job Board WordPress Theme contains a vulnerability that allows authenticated users with Subscriber-level access or higher to escalate their privileges. This flaw is a result of inadequate user identity validation when updating personal information, such as email addresses. Attackers can exploit this weakness to alter arbitrary users' email addresses, including those of administrators. By doing so, they can initiate a password reset for the affected accounts, effectively gaining unauthorized access.
Affected Version(s)
Nokri β Job Board WordPress Theme * <= 1.6.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tonn