Description
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Published: 2026-08-13
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated broken access control flaw that allows an attacker to bypass normal authorization checks for the WordPress Nokri theme. Because authentication is not required, an attacker can potentially view or modify resources that should be restricted, such as private content or theme settings. The flaw is represented by CWE-640, indicating a failure to properly enforce access control constraints. Without remediation, this could compromise the confidentiality, integrity, or availability of site data and user information.

Affected Systems

WordPress installations that have the Nokri theme version 1.6.6 or earlier. The theme is distributed by the scriptsbundle vendor under the Nokri product line. Any site using these versions of the theme is considered affected until an update to at least 1.6.7 is performed.

Risk and Exploitability

The CVSS score of 9.8 classifies this issue as critical, reflecting a high likelihood of exploitation and severe impact. EPSS information is not available, suggesting no publicly known samples yet, but the absence of a KEV listing does not diminish the potential risk. The vulnerability is remotely exploitable via the web interface, with no authentication required, making it accessible to any visitor on the internet. Given the critical severity and remote nature, the likelihood of attack remains significant until the theme is upgraded.

Generated by OpenCVE AI on August 13, 2026 at 16:10 UTC.

Remediation

Vendor Solution

Update the WordPress Nokri Theme to the latest available version (at least 1.6.7).


OpenCVE Recommended Actions

  • Update the WordPress Nokri Theme to version 1.6.7 or later.
  • After upgrading, review the site for any content that may have been accessed or altered by unauthorized users and restore it from backups if necessary.
  • Implement regular security scans for access control issues on all WordPress plugins and themes to detect similar vulnerabilities early.

Generated by OpenCVE AI on August 13, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Title WordPress Nokri theme <= 1.6.6 - Broken Access Control vulnerability
Weaknesses CWE-640
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:21:26.541Z

Reserved: 2026-07-27T14:01:04.038Z

Link: CVE-2026-66691

cve-icon Vulnrichment

Updated: 2026-08-13T15:21:22.062Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:17:10.240

Modified: 2026-08-13T16:18:46.877

Link: CVE-2026-66691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:15:04Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password