Skip to main content
Vulnerability Database/CVE-2026-18550

CVE-2026-18550: Nokri Job Board WordPress Theme Privilege Escalation

CVE-2026-18550 is a privilege escalation flaw in Nokri Job Board WordPress Theme allowing unauthenticated attackers to reset passwords and take over accounts. This post covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-18550 Overview

CVE-2026-18550 is an account takeover vulnerability in the Nokri Job Board WordPress theme affecting all versions up to and including 1.6.6. The flaw resides in the nokri_reset_password() function, which fails to properly validate password reset tokens. Empty attacker-supplied reset tokens match empty or unset sb_password_forget_token user meta values, enabling unauthenticated attackers to reset the password of any user. Successful exploitation grants full account access, including administrator accounts, leading to complete site compromise. The vulnerability is classified under CWE-269: Improper Privilege Management.

Critical Impact

Unauthenticated attackers can reset administrator passwords and take over any WordPress site running vulnerable versions of the Nokri Job Board theme.

Affected Products

  • Nokri Job Board WordPress Theme versions 1.0 through 1.6.6
  • WordPress installations using the Nokri theme distributed via ThemeForest
  • Sites relying on the nokri_reset_password() password recovery workflow

Discovery Timeline

  • 2026-09-01 - CVE-2026-18550 published to NVD
  • 2026-09-02 - Last updated in NVD database

Technical Details for CVE-2026-18550

Vulnerability Analysis

The vulnerability originates in the nokri_reset_password() function, which processes password reset requests. The function compares an attacker-supplied token value against the sb_password_forget_token user meta field stored in WordPress. When both values are empty strings or null, the loose comparison evaluates as a match. This logic error transforms the password reset workflow into an authentication bypass for any user account whose reset token meta is unset or empty by default.

Because most user accounts never trigger a password reset, the sb_password_forget_token meta field remains empty or absent. Attackers exploit this precondition to target administrator accounts directly.

Root Cause

The root cause is insufficient token validation. The reset routine does not verify that a reset was actually requested, does not enforce a minimum token length, and does not reject empty values before comparison. This is a classic CWE-269 privilege management failure, where the authorization decision hinges on an easily-forged input.

Attack Vector

Exploitation requires no authentication and no user interaction. An attacker sends a crafted HTTP request to the theme's password reset endpoint, supplying a target username or email and an empty token value. The server compares the empty token against the empty user meta, accepts the reset, and applies an attacker-chosen password. The attacker then logs in with the new credentials and inherits the target's privileges. When targeting an administrator, this yields full control over the WordPress site, including plugin and theme code execution.

No verified proof-of-concept code is publicly available. Technical details are documented in the Wordfence Vulnerability Analysis.

Detection Methods for CVE-2026-18550

Indicators of Compromise

  • Unexpected password changes on administrator or editor accounts without corresponding user-initiated reset requests
  • Successful WordPress logins from unfamiliar IP addresses immediately following requests to the Nokri password reset endpoint
  • Creation of new administrator accounts, plugin installations, or theme modifications after suspicious reset activity
  • Web server access logs showing repeated POST requests to reset handlers with missing or empty token parameters

Detection Strategies

  • Inspect WordPress wp_usermeta for anomalous updates to sb_password_forget_token and correlate with password hash changes in wp_users
  • Monitor HTTP request bodies to password reset endpoints for empty or missing token fields
  • Alert on administrator authentication events that immediately follow password reset traffic from the same or related source IPs

Monitoring Recommendations

  • Forward WordPress authentication and user modification events to a centralized logging platform for correlation and retention
  • Enable file integrity monitoring on wp-content/themes/nokri/ and core WordPress files to detect post-compromise tampering
  • Track outbound connections from the web server to identify webshell callbacks or backdoor activity following a successful takeover

How to Mitigate CVE-2026-18550

Immediate Actions Required

  • Update the Nokri Job Board theme to a version later than 1.6.6 as soon as the vendor releases a patched release
  • Force a password reset for all administrator and privileged accounts on affected WordPress installations
  • Audit the wp_users and wp_usermeta tables for unauthorized account changes and remove any rogue administrator accounts
  • Review installed plugins, themes, and uploaded files for backdoors introduced during any window of exposure

Patch Information

At the time of publication, refer to the NokriWP homepage and the Wordfence advisory for the latest patched version. Apply the vendor-supplied update through the WordPress admin dashboard or by replacing the theme files via SFTP.

Workarounds

  • Restrict access to the theme's password reset endpoint using web application firewall (WAF) rules that reject requests containing empty token parameters
  • Temporarily disable the Nokri theme's front-end password reset functionality if a patch is not yet available
  • Enforce multi-factor authentication (MFA) on administrator accounts to reduce the impact of a successful password reset
  • Limit administrative access by IP allowlist at the web server or WAF layer until patching is complete
bash
# Example WAF rule concept: block empty token parameters on Nokri reset endpoint
# ModSecurity pseudo-rule
SecRule REQUEST_URI "@contains nokri_reset_password" \
  "chain,deny,status:403,id:1026018550,msg:'CVE-2026-18550 empty token'"
SecRule ARGS:token "@rx ^$"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.