CRITICAL
9.8 CVE-2026-18550 Published 1 Sept 2026
Nokri WordPress Theme Password Reset Bug
Worried this affects one of your servers?
The Nokri - Job Board WordPress Theme is affected by a Privilege Escalation vulnerability via Account Takeover.
In versions up to 1.6.6, the theme allows attackers to reset the password of any user, including administrators, by exploiting an insufficient reset token validation issue in the nokri_reset_password() function.
Reference: CVE-2026-18550 on NVD
← Back to Security News