CVE-2025-9049 Overview
The Nokri – Job Board WordPress Theme contains a missing authorization vulnerability [CWE-862] in the nokri_account_member_permissions function. All versions up to and including 1.6.4 are affected. Authenticated attackers with Subscriber-level access can add new Subscriber users with employer account member permissions. Those newly created accounts can then update the email address of any user, including Administrator accounts, enabling full account takeover through password reset flows. The flaw affects the theme's account member permission handling and requires only low-privileged access to exploit.
Critical Impact
A Subscriber-level attacker can escalate to full Administrator control of a WordPress site running Nokri 1.6.4 or earlier by hijacking any user's email address.
Affected Products
- Nokri – Job Board WordPress Theme, versions 1.0 through 1.6.4
Discovery Timeline
- 2026-09-05 - CVE-2025-9049 published to NVD
- 2026-09-08 - Last updated in NVD database
Technical Details for CVE-2025-9049
Vulnerability Analysis
The vulnerability is a broken access control issue in the Nokri theme's nokri_account_member_permissions function. The function processes requests to assign employer account member permissions to WordPress users but does not verify that the calling user holds the appropriate capability. Any authenticated user, including a default Subscriber, can invoke the function through its exposed endpoint.
Exploitation proceeds in two stages. First, the attacker calls the vulnerable function to create a new Subscriber account and assign it employer account member permissions. Second, the attacker uses those permissions to modify arbitrary user attributes. Because the permission set allows updating the email address field on any user record, the attacker changes the Administrator email to an attacker-controlled address. A standard WordPress password reset against the modified account then grants the attacker Administrator credentials.
The combination of missing capability checks and overly broad member-permission scope results in a two-step privilege escalation from Subscriber to Administrator.
Root Cause
The root cause is the absence of a current_user_can() capability check within the nokri_account_member_permissions handler. WordPress themes must gate privileged actions behind explicit capability validation. Without this check, any authenticated session bypasses authorization entirely. The design also grants member permissions broader control over user records than necessary, violating least privilege.
Attack Vector
The attack vector is network based over HTTP or HTTPS. The attacker requires a valid low-privileged WordPress account, which is trivially obtainable on sites that allow open registration, a default configuration on job board deployments. User interaction from the victim is not required. See the Wordfence Vulnerability Report for the underlying research.
Detection Methods for CVE-2025-9049
Indicators of Compromise
- Unexpected new Subscriber accounts created in short succession, particularly with employer-related metadata attached.
- Email address changes on Administrator or Editor accounts that do not correlate with legitimate profile updates.
- Password reset emails sent to unfamiliar external domains for privileged accounts.
- WordPress audit log entries referencing calls to nokri_account_member_permissions from non-administrative users.
Detection Strategies
- Monitor WordPress AJAX and admin-ajax request logs for invocations of the nokri_account_member_permissions action originating from Subscriber sessions.
- Alert on any user_email field update on accounts holding the administrator role.
- Correlate new user registrations with subsequent privileged user modifications within short time windows.
Monitoring Recommendations
- Ingest WordPress access logs and application audit trails into a centralized log analytics pipeline for behavioral review.
- Enable file integrity monitoring on the wp-content/themes/nokri/ directory to identify unauthorized theme modifications.
- Track outbound email traffic from the WordPress host for anomalous password reset activity.
How to Mitigate CVE-2025-9049
Immediate Actions Required
- Upgrade the Nokri theme to a version later than 1.6.4 once a patched release is available from the vendor.
- Audit all WordPress user accounts and remove any unexpected Subscriber or employer member accounts.
- Reset passwords and verify email addresses for all Administrator and Editor accounts.
- Disable open user registration on the affected site until the patch is applied.
Patch Information
Review the Nokri Theme Change Logs for the fixed version and apply the update via the WordPress theme updater or by replacing the theme files on disk. Confirm the fix by validating that nokri_account_member_permissions performs a capability check before executing privileged logic.
Workarounds
- Set users_can_register to false in WordPress general settings to block anonymous account creation.
- Deploy a web application firewall rule that blocks requests to the nokri_account_member_permissions action from users without administrator capabilities.
- Restrict the theme's AJAX endpoints at the reverse proxy layer to authenticated administrative sessions only.
# Disable open user registration via WP-CLI
wp option update users_can_register 0
# List recently created Subscriber accounts for review
wp user list --role=subscriber --fields=ID,user_login,user_email,user_registered --orderby=user_registered --order=DESC
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
