Impact
The Nokri – Job Board WordPress Theme contains a missing capability check in the 'nokri_account_member_permissions' function, allowing any authenticated user with Subscriber-level access or higher to add new Subscriber accounts that are granted employer account member permissions. These elevated accounts can then change the email address of any user, including Administrators, effectively hijacking their accounts. This flaw enables an attacker to gain full control of the WordPress installation by elevating privileges through account takeover.
Affected Systems
All installations of the Nokri – Job Board WordPress Theme with version 1.6.4 or earlier are impacted. Users employing this theme must verify their current version and confirm whether they are running a vulnerable release.
Risk and Exploitability
The vulnerability is rated high with a CVSS score of 8.8. No EPSS score is available and the flaw is not listed in the CISA KEV catalog. Exploitation requires authenticated access, specifically a Subscriber account or higher. Once an attacker gains entry, they can add privileged users and modify email addresses, potentially taking over administrator accounts without further external interaction.
OpenCVE Enrichment