← WordPress Vulnerabilities
WordPress security by component

Nokri – Job Board WordPress Theme

Nokri – Job Board WordPress Theme (nokri-job-board-wordpress-theme) is a WordPress theme with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 9.8.

Theme slug: nokri-job-board-wordpress-theme

CVE-2025-9049: Nokri permits Subscriber-level administrator account takeover

Nokri through 1.6.4 omits a capability check in nokri_account_member_permissions(). A Subscriber can add employer account members, then use that delegated access to change the email address of any account, including an Administrator, and take over the account.

PublishedSep 05, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for nokri-job-board-wordpress-theme
Safe version
Sep 05, 2026 CVE-2025-9049
Nokri permits Subscriber-level administrator account takeover
Nokri through 1.6.4 omits a capability check in nokri_account_member_permissions(). A Subscriber can add employer account members, then use that delegated access to change the email address of any account, including an Administrator, and take over the account.
See mitigation notes
CVE8.8
NVDPending
Jul 12, 2025 CVE-2025-1313
Nokri - Job Board: Privilege escalation or authentication bypass
Nokri - Job Board is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Mar 01, 2025 CVE-2024-12824
Nokri – Job Board: Privilege escalation or authentication bypass
Nokri – Job Board is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending