PT-2026-84146 · WordPress · Nokri
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nokri - Job Board WordPress Theme versions prior to 1.6.7
Description
Insufficient reset token validation in the
nokri reset password() function allows unauthenticated attackers to perform privilege escalation via account takeover. By providing an empty reset token in the token parameter, an attacker can match empty or unset sb password forget token user meta values, enabling the password reset of any user, including administrators.Recommendations
Update to a version newer than 1.6.6.
As a temporary workaround, restrict access to the password reset functionality until the update is applied.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nokri