Impact
The vulnerability in the Nokri – Job Board WordPress Theme permits an attacker to reset any user password by exploiting insufficient validation of the reset token parameter. A(n) unauthenticated attacker can supply an empty token that matches empty or unset metadata in the database, allowing the attacker to change the password of administrators or any user. This enables full account takeover, compromising confidentiality and integrity of site administration. The weakness is a classic Password Reset (Reset Token) bypass, classified as CWE-269.
Affected Systems
The affected product is the Nokri – Job Board WordPress Theme published by scriptsbundle, in all released versions up to and including 1.6.6. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the public password‑reset endpoint, accessed over HTTP/HTTPS by an unauthenticated user. Based on the description, it is inferred that an attacker can craft a request to the reset URL with an empty or missing token parameter to trigger the exploit.
OpenCVE Enrichment