Privilege Escalation Vulnerability in Nokri Job Board WordPress Theme
CVE-2026-18550

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 September 2026

What is CVE-2026-18550?

The Nokri - Job Board WordPress Theme is susceptible to a privilege escalation issue that enables unauthenticated attackers to take over user accounts. This vulnerability arises from inadequate validation of reset tokens in the 'nokri_reset_password()' function. Attackers can exploit this weakness by submitting empty reset tokens, which can falsely match empty or unset user meta values for password reset tokens. Consequently, any user’s password, including those of administrators, can be reset, allowing unauthorized access to their accounts.

Affected Version(s)

Nokri – Job Board WordPress Theme 0 <= 1.6.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d.v4n_s3c
.