Privilege Escalation Vulnerability in Nokri Job Board WordPress Theme
CVE-2026-18550
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-18550?
The Nokri - Job Board WordPress Theme is susceptible to a privilege escalation issue that enables unauthenticated attackers to take over user accounts. This vulnerability arises from inadequate validation of reset tokens in the 'nokri_reset_password()' function. Attackers can exploit this weakness by submitting empty reset tokens, which can falsely match empty or unset user meta values for password reset tokens. Consequently, any user’s password, including those of administrators, can be reset, allowing unauthorized access to their accounts.
Affected Version(s)
Nokri – Job Board WordPress Theme 0 <= 1.6.6