Impact
The Nokri WordPress theme contains a Cross‑Site Request Forgery flaw that permits malicious actors to trigger privileged actions on behalf of authenticated users. An attacker who tricks a user into visiting a crafted URL can perform non‑destructive changes such as publishing or deleting posts, modifying settings, or changing user data, without needing the user’s credentials. The weakness resides in the lack of a server‑side CSRF token validation, and is categorized as CWE‑352.
Affected Systems
The vulnerability affects all installations of the Nokri theme from the earliest release through version 1.6.4. The theme is provided by scriptsbundle and used on WordPress sites that have incorporated Nokri. Sites that have not yet upgraded beyond 1.6.4 remain susceptible.
Risk and Exploitability
With a CVSS score of 7.1 the issue is considered high impact. The EPSS score of <1% indicates a very low likelihood of exploitation. It is not part of the CISA KEV list, suggesting no confirmed widespread attacks. The attack vector is inferred to be remote, as the flaw is triggered by a crafted HTTP request sent by a malicious website or link.
OpenCVE Enrichment
EUVD