CVE-2026-18550 Overview
CVE-2026-18550 is an account takeover vulnerability in the Nokri Job Board WordPress theme affecting all versions up to and including 1.6.6. The flaw resides in the nokri_reset_password() function, which fails to properly validate password reset tokens. Empty attacker-supplied reset tokens match empty or unset sb_password_forget_token user meta values, enabling unauthenticated attackers to reset the password of any user. Successful exploitation grants full account access, including administrator accounts, leading to complete site compromise. The vulnerability is classified under CWE-269: Improper Privilege Management.
Critical Impact
Unauthenticated attackers can reset administrator passwords and take over any WordPress site running vulnerable versions of the Nokri Job Board theme.
Affected Products
- Nokri Job Board WordPress Theme versions 1.0 through 1.6.6
- WordPress installations using the Nokri theme distributed via ThemeForest
- Sites relying on the nokri_reset_password() password recovery workflow
Discovery Timeline
- 2026-09-01 - CVE-2026-18550 published to NVD
- 2026-09-02 - Last updated in NVD database
Technical Details for CVE-2026-18550
Vulnerability Analysis
The vulnerability originates in the nokri_reset_password() function, which processes password reset requests. The function compares an attacker-supplied token value against the sb_password_forget_token user meta field stored in WordPress. When both values are empty strings or null, the loose comparison evaluates as a match. This logic error transforms the password reset workflow into an authentication bypass for any user account whose reset token meta is unset or empty by default.
Because most user accounts never trigger a password reset, the sb_password_forget_token meta field remains empty or absent. Attackers exploit this precondition to target administrator accounts directly.
Root Cause
The root cause is insufficient token validation. The reset routine does not verify that a reset was actually requested, does not enforce a minimum token length, and does not reject empty values before comparison. This is a classic CWE-269 privilege management failure, where the authorization decision hinges on an easily-forged input.
Attack Vector
Exploitation requires no authentication and no user interaction. An attacker sends a crafted HTTP request to the theme's password reset endpoint, supplying a target username or email and an empty token value. The server compares the empty token against the empty user meta, accepts the reset, and applies an attacker-chosen password. The attacker then logs in with the new credentials and inherits the target's privileges. When targeting an administrator, this yields full control over the WordPress site, including plugin and theme code execution.
No verified proof-of-concept code is publicly available. Technical details are documented in the Wordfence Vulnerability Analysis.
Detection Methods for CVE-2026-18550
Indicators of Compromise
- Unexpected password changes on administrator or editor accounts without corresponding user-initiated reset requests
- Successful WordPress logins from unfamiliar IP addresses immediately following requests to the Nokri password reset endpoint
- Creation of new administrator accounts, plugin installations, or theme modifications after suspicious reset activity
- Web server access logs showing repeated POST requests to reset handlers with missing or empty token parameters
Detection Strategies
- Inspect WordPress wp_usermeta for anomalous updates to sb_password_forget_token and correlate with password hash changes in wp_users
- Monitor HTTP request bodies to password reset endpoints for empty or missing token fields
- Alert on administrator authentication events that immediately follow password reset traffic from the same or related source IPs
Monitoring Recommendations
- Forward WordPress authentication and user modification events to a centralized logging platform for correlation and retention
- Enable file integrity monitoring on wp-content/themes/nokri/ and core WordPress files to detect post-compromise tampering
- Track outbound connections from the web server to identify webshell callbacks or backdoor activity following a successful takeover
How to Mitigate CVE-2026-18550
Immediate Actions Required
- Update the Nokri Job Board theme to a version later than 1.6.6 as soon as the vendor releases a patched release
- Force a password reset for all administrator and privileged accounts on affected WordPress installations
- Audit the wp_users and wp_usermeta tables for unauthorized account changes and remove any rogue administrator accounts
- Review installed plugins, themes, and uploaded files for backdoors introduced during any window of exposure
Patch Information
At the time of publication, refer to the NokriWP homepage and the Wordfence advisory for the latest patched version. Apply the vendor-supplied update through the WordPress admin dashboard or by replacing the theme files via SFTP.
Workarounds
- Restrict access to the theme's password reset endpoint using web application firewall (WAF) rules that reject requests containing empty token parameters
- Temporarily disable the Nokri theme's front-end password reset functionality if a patch is not yet available
- Enforce multi-factor authentication (MFA) on administrator accounts to reduce the impact of a successful password reset
- Limit administrative access by IP allowlist at the web server or WAF layer until patching is complete
# Example WAF rule concept: block empty token parameters on Nokri reset endpoint
# ModSecurity pseudo-rule
SecRule REQUEST_URI "@contains nokri_reset_password" \
"chain,deny,status:403,id:1026018550,msg:'CVE-2026-18550 empty token'"
SecRule ARGS:token "@rx ^$"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
